Req #71231 [Asn->Nab]: parse_url doesn't urldecode urlencoded characters
Edit report at https://bugs.php.net/bug.php?id=71231&edit=1
ID: 71231
Updated by: willfitch@php.net
Reported by: zelnaga at gmail dot com
Summary: parse_url doesn't urldecode urlencoded characters
-Status: Assigned
+Status: Not a bug
Type: Feature/Change Request
Package: URL related
Operating System: Windows 7
PHP Version: 7.0.1
Assigned To: willfitch
Block user comment: N
Private report: N
New Comment:
Take that back - I forgot parse_url doesn't actually decode anything other than control
characters. urldecode *does* decode the value correctly.
@zelnaga - if you need to decode, use urldecode.
Previous Comments:
------------------------------------------------------------------------
[2016-02-01 16:29:54] willfitch@php.net
@yohgaki - I completely agree it would result in unexpected behaviors for previous versions, but
this is a bug. The path is never decoded - and that isn't double decoding. Decoding the
path/file AND query parameters should be the expected behavior. It is for pretty much every other
language as well.
For the BC concern, this would be addressing a bug, so I don't agree that we'd
"break" backwards compatibility - but rather fix it.
------------------------------------------------------------------------
[2016-01-15 08:07:33] simonsimcity at gmail dot com
I don't think it should be decoded at that level here.
Think of requests like the following:
var_dump(parse_url("/?foo=ab%26bar%3Dfoo"));
var_dump(parse_url(urldecode("/?foo=ab%26bar%3Dfoo")));
var_dump(parse_url("/foo%2Fab/bar"));
var_dump(parse_url(urldecode("/foo%2Fab/bar")));
I guess the last one is negligible, but I could well see the first example ...
------------------------------------------------------------------------
[2015-12-29 04:16:30] zelnaga at gmail dot com
Double decoding would be a BC breaking change but none-the-less I believe it's the correct
behavior to decode. If you make an HTTP request to that URL Google's webserver decodes it as
/search?q=test .
Like if you do /search?q=te%28st you'd get q=te%28st in the query part of the array but I
believe it should be q=te#st because that's what the web server wold see with
$_GET['q'] - not te%28st.
------------------------------------------------------------------------
[2015-12-28 20:50:37] yohgaki@php.net
If anyone care to implement decoding feature, please _never_ decode by default, since
double(multiple) decoding is a cause of security issues.
------------------------------------------------------------------------
[2015-12-28 20:47:30] yohgaki@php.net
This is not a bug.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71231
--
Edit this bug report at https://bugs.php.net/bug.php?id=71231&edit=1
Thread (7 messages)