Bug #71822 [Com]: parse_url on 7.1.0-dev returns false where password contains a `-` character

From: Date: Fri, 07 Oct 2016 20:39:54 +0000
Subject: Bug #71822 [Com]: parse_url on 7.1.0-dev returns false where password contains a `-` character
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204537@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71822&edit=1 ID: 71822 Comment by: cilefen at gmail dot com Reported by: nigel dot greenway at futurepixels dot co dot uk Summary: parse_url on 7.1.0-dev returns false where password contains a - character Status: Open Type: Bug Package: *URL Functions Operating System: Linux - BunsenLabs PHP Version: Next Major Version Block user comment: N Private report: N New Comment: Underscores "_" also cause a return of false. Previous Comments: ------------------------------------------------------------------------ [2016-10-07 20:16:18] cilefen at gmail dot com This is causing test failures in Drupal 8 HEAD, https://www.drupal.org/node/2813981. ------------------------------------------------------------------------ [2016-09-07 14:51:13] andi at splitbrain dot org The same problem occurs with a space in the password. I am aware that this might not be a valid URL as is (space should be escaped) however this used to work on PHP 7.0 <?php $x = parse_url('http://foo:foo bar@example.com/'); var_dump($x); ?> ------------------------------------------------------------------------ [2016-03-15 07:09:24] yohgaki@php.net https://3v4l.org/UusRf It seems released versions are fine. unreserved = ALPHA / DIGIT / "-" / "." / "_" / "~" pct-encoded = "%" HEXDIG HEXDIG sub-delims = "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "=" userinfo = *( unreserved / pct-encoded / sub-delims / ":" ) https://www.ietf.org/rfc/rfc3986.txt "so-me:pass-word" should be valid username and password. According to the RFC, "Use of the format "user:password" in the userinfo field is deprecated.", but we need to support this format anyway. ------------------------------------------------------------------------ [2016-03-14 13:52:08] derick@php.net I've tried this and can reproduce this. It's changed from PHP 7.0.3 where having a - works fine. ------------------------------------------------------------------------ [2016-03-14 13:40:01] nigel dot greenway at futurepixels dot co dot uk Description: ------------ Passing hyphenated username and passwords as part of a url to url_parse returns false. Test script: --------------- <?php var_dump( parse_url('http://some:password@ex-ample.co.uk'), parse_url('http://so-me:password@192.168.0.123'), parse_url('http://some:pass-word@192.168.0.123') ); Expected result: ---------------- array(4) { ["scheme"]=> string(4) "http" ["host"]=> string(14) "ex-ample.co.uk" ["user"]=> string(4) "some" ["pass"]=> string(8) "password" } array(4) { ["scheme"]=> string(4) "http" ["host"]=> string(14) "192.168.0.123" ["user"]=> string(4) "so-me" ["pass"]=> string(8) "password" } array(4) { ["scheme"]=> string(4) "http" ["host"]=> string(14) "192.168.0.123" ["user"]=> string(4) "some" ["pass"]=> string(8) "pass-word" } Actual result: -------------- array(4) { ["scheme"]=> string(4) "http" ["host"]=> string(14) "ex-ample.co.uk" ["user"]=> string(4) "some" ["pass"]=> string(8) "password" } bool(false) bool(false) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71822&edit=1

« previous php.bugs (#204537) next »