Bug #72977 [Opn->Nab]: cURL uses wrong domain when using user names with @ sign
| From: | requinix@php.net | Date: | Tue, 30 Aug 2016 22:09:55 +0000 |
| Subject: | Bug #72977 [Opn->Nab]: cURL uses wrong domain when using user names with @ sign | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203691@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72977&edit=1
ID: 72977
Updated by: requinix@php.net
Reported by: rlwedelschaap at gmail dot com
Summary: cURL uses wrong domain when using user names with @
sign
-Status: Open
+Status: Not a bug
Type: Bug
Package: cURL related
Operating System: Ubuntu 16.04 LTS
PHP Version: 7.0.10
Block user comment: N
Private report: N
New Comment:
As per RFC 3986 the only characters permitted for a username or password are letters, digits, %s
used for percent encoding, and -._~!$&'()*+,;= so any @s must be encoded.
Use rawurlencode() on the username and password (separately) before putting them into the URL.
$user = rawurlencode('user@domain.com');
$password = rawurlencode('password');
$url = "http://{$user}:{$password}@www.example.com/page.html";
Previous Comments:
------------------------------------------------------------------------
[2016-08-30 14:37:31] rlwedelschaap at gmail dot com
Description:
------------
When using a user name and password for basic authentication in the URL directly, cURL will try to
resolve the domain from the user name when the user name contains an @ sign instead of the actual
domain.
This results in
a) requesting the wrong URL when the domain in the user name exists;
b) a "Could not resolve host" error when the domain in the user name does not exist.
Test script:
---------------
<?php
$curl = curl_init();
curl_setopt_array( $curl, [
CURLOPT_FOLLOWLOCATION => true,
CURLOPT_FORBID_REUSE => true,
CURLOPT_FRESH_CONNECT => true,
CURLOPT_HEADER => false,
CURLOPT_HTTPHEADER => [
'Accept:
text/html,application/json,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8',
'Accept-Charset: UTF-8',
'Connection: close',
'Content-Type: charset=UTF-8',
],
CURLOPT_MAXREDIRS => 3,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_SSL_VERIFYPEER => false,
CURLOPT_TIMEOUT => 30,
CURLOPT_URL => 'http://user@domain.com:password@www.example.com/page.html',
] );
$response = curl_exec( $curl );
if ( $response !== false ) {
echo 'Completed cURL exec';
print_r( curl_getinfo( $curl ) );
} else {
echo 'Error: ' . curl_error( $curl );
print_r( curl_getinfo( $curl ) );
}
Expected result:
----------------
Completed cURL exec
Array
(
[url] => http://user@domain.com:password@www.example.com/page.html
[content_type] => text/html; charset=UTF-8
[http_code] => 200
...
)
/* $response should contain the HTML page of http://www.example.com/page.html */
Actual result:
--------------
Completed cURL exec
Array
(
[url] => http://www.domain.com/page
[content_type] => text/html; charset=UTF-8
[http_code] => 200
...
)
/* In this scenario, $response contains the HTML page of http://www.domain.com/page */
===== Or, when using a non-existing domain in the user name =====
Error: Could not resolve host: a-non-existing-domain.com
Array
(
[url] => http://user@a-non-existing-domain.com:password@www.example.com/page.html
[content_type] =>
[http_code] => 0
...
)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72977&edit=1