Bug #72348 [Opn->Nab]: Ignored variable value in if-request when switching the var type
| From: | cmb@php.net | Date: | Mon, 06 Jun 2016 18:47:48 +0000 |
| Subject: | Bug #72348 [Opn->Nab]: Ignored variable value in if-request when switching the var type | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201490@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72348&edit=1
ID: 72348
Updated by: cmb@php.net
Reported by: toastboot at gmx dot de
Summary: Ignored variable value in if-request when switching
the var type
-Status: Open
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: Win 7
PHP Version: 5.6.22
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Particularly, see <http://php.net/manual/en/types.comparisons.php>.
Previous Comments:
------------------------------------------------------------------------
[2016-06-06 18:34:32] toastboot at gmx dot de
Description:
------------
In advance I have to say, that it is not version 5.6.22 but 5.6.3 (german XAMPP installation) where
I found the issue. I can't find this version in your list. Maybe you can change your list and
then refer it correctly?!?
Normally I like the variable handling in PHP, that includes the possibility to be able to switch
between var types but there is an issue with the var types. It can occur that an if-request will
ignore the variable value... See more in the test script / example as follows...
Additional warning: I have not made any deeper checks but maybe it can cause security issues. In a
simple check I saw, that it seems not to be possible to cause this issue via GET. There it works
correctly (in my test scenario) but maybe there are other possibilities...
Test script:
---------------
$the_variable = 0;
/* make sth */
if($the_variable == "stop") {
# 'the_variable' is still set to 0
echo "hello";
}
# This will cause the wrong behaviour that the code within the if-request will be executed /
'hello' is displayed.
# now try it vice versa:
$the_variable = "stop";
if($the_variable == 0) {
echo "hello";
}
# The second if-request works as expected.
## Workaround ##
# use '===' instead of '=='
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72348&edit=1