Bug #72301 [Opn]: filter_var($url, FILTER_VALIDATE_URL) does not support scheme-relative URLs

From: Date: Tue, 31 May 2016 10:07:07 +0000
Subject: Bug #72301 [Opn]: filter_var($url, FILTER_VALIDATE_URL) does not support scheme-relative URLs
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201364@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72301&edit=1

 ID:                 72301
 Updated by:         derick@php.net
 Reported by:        ian+php at ians-net dot co dot uk
 Summary:            filter_var($url, FILTER_VALIDATE_URL) does not
                     support scheme-relative URLs
 Status:             Open
 Type:               Bug
 Package:            Filter related
 Operating System:   OpenBSD
 PHP Version:        7.0.7
 Block user comment: N
 Private report:     N

 New Comment:

If this gets added, it should be done with an optional (off by default) new flag.


Previous Comments:
------------------------------------------------------------------------
[2016-05-31 09:26:53] ian+php at ians-net dot co dot uk

Description:
------------
RFC3986 allows scheme relative URLs, also termed network-path references. These are commonly used to
ensure the appropriate protocol is used to fetch the resource regardless of whether the resource is
embedded in a http or https page.

filter_var($url, FILTER_VALIDATE_URL) does not correctly validate these URLs

See also
 https://tools.ietf.org/html/rfc3986#section-4.2
 https://url.spec.whatwg.org/#syntax-url-scheme-relative

Test script:
---------------
var_dump(filter_var("//google.com/", FILTER_VALIDATE_URL));



Expected result:
----------------
bool(true)

Actual result:
--------------
bool(false)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72301&edit=1


Thread (5 messages)

« previous php.bugs (#201364) next »