Bug #72977 [Opn->Nab]: cURL uses wrong domain when using user names with @ sign

From: Date: Tue, 30 Aug 2016 22:09:55 +0000
Subject: Bug #72977 [Opn->Nab]: cURL uses wrong domain when using user names with @ sign
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203691@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72977&edit=1 ID: 72977 Updated by: requinix@php.net Reported by: rlwedelschaap at gmail dot com Summary: cURL uses wrong domain when using user names with @ sign -Status: Open +Status: Not a bug Type: Bug Package: cURL related Operating System: Ubuntu 16.04 LTS PHP Version: 7.0.10 Block user comment: N Private report: N New Comment: As per RFC 3986 the only characters permitted for a username or password are letters, digits, %s used for percent encoding, and -._~!$&'()*+,;= so any @s must be encoded. Use rawurlencode() on the username and password (separately) before putting them into the URL. $user = rawurlencode('user@domain.com'); $password = rawurlencode('password'); $url = "http://{$user}:{$password}@www.example.com/page.html"; Previous Comments: ------------------------------------------------------------------------ [2016-08-30 14:37:31] rlwedelschaap at gmail dot com Description: ------------ When using a user name and password for basic authentication in the URL directly, cURL will try to resolve the domain from the user name when the user name contains an @ sign instead of the actual domain. This results in a) requesting the wrong URL when the domain in the user name exists; b) a "Could not resolve host" error when the domain in the user name does not exist. Test script: --------------- <?php $curl = curl_init(); curl_setopt_array( $curl, [ CURLOPT_FOLLOWLOCATION => true, CURLOPT_FORBID_REUSE => true, CURLOPT_FRESH_CONNECT => true, CURLOPT_HEADER => false, CURLOPT_HTTPHEADER => [ 'Accept: text/html,application/json,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Charset: UTF-8', 'Connection: close', 'Content-Type: charset=UTF-8', ], CURLOPT_MAXREDIRS => 3, CURLOPT_RETURNTRANSFER => true, CURLOPT_SSL_VERIFYPEER => false, CURLOPT_TIMEOUT => 30, CURLOPT_URL => 'http://user@domain.com:password@www.example.com/page.html', ] ); $response = curl_exec( $curl ); if ( $response !== false ) { echo 'Completed cURL exec'; print_r( curl_getinfo( $curl ) ); } else { echo 'Error: ' . curl_error( $curl ); print_r( curl_getinfo( $curl ) ); } Expected result: ---------------- Completed cURL exec Array ( [url] => http://user@domain.com:password@www.example.com/page.html [content_type] => text/html; charset=UTF-8 [http_code] => 200 ... ) /* $response should contain the HTML page of http://www.example.com/page.html */ Actual result: -------------- Completed cURL exec Array ( [url] => http://www.domain.com/page [content_type] => text/html; charset=UTF-8 [http_code] => 200 ... ) /* In this scenario, $response contains the HTML page of http://www.domain.com/page */ ===== Or, when using a non-existing domain in the user name ===== Error: Could not resolve host: a-non-existing-domain.com Array ( [url] => http://user@a-non-existing-domain.com:password@www.example.com/page.html [content_type] => [http_code] => 0 ... ) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72977&edit=1

« previous php.bugs (#203691) next »