Bug #72977 [NEW]: cURL uses wrong domain when using user names with @ sign

From: Date: Tue, 30 Aug 2016 14:37:35 +0000
Subject: Bug #72977 [NEW]: cURL uses wrong domain when using user names with @ sign
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203684@lists.php.net to get a copy of this message
From: rlwedelschaap at gmail dot com Operating system: Ubuntu 16.04 LTS PHP version: 7.0.10 Package: cURL related Bug Type: Bug Bug description:cURL uses wrong domain when using user names with @ sign Description: ------------ When using a user name and password for basic authentication in the URL directly, cURL will try to resolve the domain from the user name when the user name contains an @ sign instead of the actual domain. This results in a) requesting the wrong URL when the domain in the user name exists; b) a "Could not resolve host" error when the domain in the user name does not exist. Test script: --------------- <?php $curl = curl_init(); curl_setopt_array( $curl, [ CURLOPT_FOLLOWLOCATION => true, CURLOPT_FORBID_REUSE => true, CURLOPT_FRESH_CONNECT => true, CURLOPT_HEADER => false, CURLOPT_HTTPHEADER => [ 'Accept: text/html,application/json,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Charset: UTF-8', 'Connection: close', 'Content-Type: charset=UTF-8', ], CURLOPT_MAXREDIRS => 3, CURLOPT_RETURNTRANSFER => true, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_TIMEOUT => 30, CURLOPT_URL => 'http://user@domain.com:password@www.example.com/page.html', ] ); $response = curl_exec( $curl ); if ( $response !== false ) { echo 'Completed cURL exec'; print_r( curl_getinfo( $curl ) ); } else { echo 'Error: ' . curl_error( $curl ); print_r( curl_getinfo( $curl ) ); } Expected result: ---------------- Completed cURL exec Array ( [url] => http://user@domain.com:password@www.example.com/page.html [content_type] => text/html; charset=UTF-8 [http_code] => 200 ... ) /* $response should contain the HTML page of http://www.example.com/page.html */ Actual result: -------------- Completed cURL exec Array ( [url] => http://www.domain.com/page [content_type] => text/html; charset=UTF-8 [http_code] => 200 ... ) /* In this scenario, $response contains the HTML page of http://www.domain.com/page */ ===== Or, when using a non-existing domain in the user name ===== Error: Could not resolve host: a-non-existing-domain.com Array ( [url] => http://user@a-non-existing-domain.com:password@www.example.com/page.html [content_type] => [http_code] => 0 ... ) -- Edit bug report at https://bugs.php.net/bug.php?id=72977&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72977&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72977&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72977&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72977&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72977&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72977&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72977&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72977&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72977&r=support Expected behavior: https://bugs.php.net/fix.php?id=72977&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72977&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72977&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72977&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72977&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72977&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72977&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72977&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72977&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72977&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72977&r=mysqlcfg

« previous php.bugs (#203684) next »