Req #71231 [Asn->Nab]: parse_url doesn't urldecode urlencoded characters

From: Date: Mon, 01 Feb 2016 17:25:46 +0000
Subject: Req #71231 [Asn->Nab]: parse_url doesn't urldecode urlencoded characters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198993@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71231&edit=1

 ID:                 71231
 Updated by:         willfitch@php.net
 Reported by:        zelnaga at gmail dot com
 Summary:            parse_url doesn't urldecode urlencoded characters
-Status:             Assigned
+Status:             Not a bug
 Type:               Feature/Change Request
 Package:            URL related
 Operating System:   Windows 7
 PHP Version:        7.0.1
 Assigned To:        willfitch
 Block user comment: N
 Private report:     N

 New Comment:

Take that back - I forgot parse_url doesn't actually decode anything other than control
characters. urldecode *does* decode the value correctly.

@zelnaga - if you need to decode, use urldecode.


Previous Comments:
------------------------------------------------------------------------
[2016-02-01 16:29:54] willfitch@php.net

@yohgaki - I completely agree it would result in unexpected behaviors for previous versions, but
this is a bug.  The path is never decoded - and that isn't double decoding.  Decoding the
path/file AND query parameters should be the expected behavior.  It is for pretty much every other
language as well.

For the BC concern, this would be addressing a bug, so I don't agree that we'd
"break" backwards compatibility - but rather fix it.

------------------------------------------------------------------------
[2016-01-15 08:07:33] simonsimcity at gmail dot com

I don't think it should be decoded at that level here.
Think of requests like the following:

var_dump(parse_url("/?foo=ab%26bar%3Dfoo"));
var_dump(parse_url(urldecode("/?foo=ab%26bar%3Dfoo")));

var_dump(parse_url("/foo%2Fab/bar"));
var_dump(parse_url(urldecode("/foo%2Fab/bar")));

I guess the last one is negligible, but I could well see the first example ...

------------------------------------------------------------------------
[2015-12-29 04:16:30] zelnaga at gmail dot com

Double decoding would be a BC breaking change but none-the-less I believe it's the correct
behavior to decode. If you make an HTTP request to that URL Google's webserver decodes it as
/search?q=test .

Like if you do /search?q=te%28st you'd get q=te%28st in the query part of the array but I
believe it should be q=te#st because that's what the web server wold see with
$_GET['q'] - not te%28st.

------------------------------------------------------------------------
[2015-12-28 20:50:37] yohgaki@php.net

If anyone care to implement decoding feature, please _never_ decode by default, since
double(multiple) decoding is a cause of security issues.

------------------------------------------------------------------------
[2015-12-28 20:47:30] yohgaki@php.net

This is not a bug.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71231


--
Edit this bug report at https://bugs.php.net/bug.php?id=71231&edit=1


Thread (7 messages)

« previous php.bugs (#198993) next »