Bug #71822 [Com]: parse_url on 7.1.0-dev returns false where password contains a `-` character
| From: | andi at splitbrain dot org | Date: | Wed, 07 Sep 2016 14:51:14 +0000 |
| Subject: | Bug #71822 [Com]: parse_url on 7.1.0-dev returns false where password contains a `-` character | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203853@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71822&edit=1
ID: 71822
Comment by: andi at splitbrain dot org
Reported by: nigel dot greenway at futurepixels dot co dot uk
Summary: parse_url on 7.1.0-dev returns false where password
contains a
- character
Status: Open
Type: Bug
Package: *URL Functions
Operating System: Linux - BunsenLabs
PHP Version: Next Major Version
Block user comment: N
Private report: N
New Comment:
The same problem occurs with a space in the password. I am aware that this might not be a valid URL
as is (space should be escaped) however this used to work on PHP 7.0
<?php
$x = parse_url('http://foo:foo bar@example.com/');
var_dump($x);
?>
Previous Comments:
------------------------------------------------------------------------
[2016-03-15 07:09:24] yohgaki@php.net
https://3v4l.org/UusRf
It seems released versions are fine.
unreserved = ALPHA / DIGIT / "-" / "." / "_" / "~"
pct-encoded = "%" HEXDIG HEXDIG
sub-delims = "!" / "$" / "&" / "'" /
"(" / ")"
/ "*" / "+" / "," / ";" / "="
userinfo = *( unreserved / pct-encoded / sub-delims / ":" )
https://www.ietf.org/rfc/rfc3986.txt
"so-me:pass-word" should be valid username and password.
According to the RFC, "Use of the format "user:password" in the userinfo field is
deprecated.", but we need to support this format anyway.
------------------------------------------------------------------------
[2016-03-14 13:52:08] derick@php.net
I've tried this and can reproduce this. It's changed from PHP 7.0.3 where having a - works
fine.
------------------------------------------------------------------------
[2016-03-14 13:40:01] nigel dot greenway at futurepixels dot co dot uk
Description:
------------
Passing hyphenated username and passwords as part of a url to url_parse returns false.
Test script:
---------------
<?php
var_dump(
parse_url('http://some:password@ex-ample.co.uk'),
parse_url('http://so-me:password@192.168.0.123'),
parse_url('http://some:pass-word@192.168.0.123')
);
Expected result:
----------------
array(4) {
["scheme"]=>
string(4) "http"
["host"]=>
string(14) "ex-ample.co.uk"
["user"]=>
string(4) "some"
["pass"]=>
string(8) "password"
}
array(4) {
["scheme"]=>
string(4) "http"
["host"]=>
string(14) "192.168.0.123"
["user"]=>
string(4) "so-me"
["pass"]=>
string(8) "password"
}
array(4) {
["scheme"]=>
string(4) "http"
["host"]=>
string(14) "192.168.0.123"
["user"]=>
string(4) "some"
["pass"]=>
string(8) "pass-word"
}
Actual result:
--------------
array(4) {
["scheme"]=>
string(4) "http"
["host"]=>
string(14) "ex-ample.co.uk"
["user"]=>
string(4) "some"
["pass"]=>
string(8) "password"
}
bool(false)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71822&edit=1