Bug #68031 [Nab]: htmlspecialchars returns empty string, sometimes

From: Date: Wed, 12 Oct 2016 21:53:56 +0000
Subject: Bug #68031 [Nab]: htmlspecialchars returns empty string, sometimes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204651@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68031&edit=1 ID: 68031 Updated by: yohgaki@php.net Reported by: pfenderd at bellsouth dot net Summary: htmlspecialchars returns empty string, sometimes Status: Not a bug Type: Bug Package: Filter related Operating System: Linux PHP Version: 5.5.16 Assigned To: cmb Block user comment: N Private report: N New Comment: Users should validate _all_ input strings if they have valid char encoding you specified by default_charset. Use mb_check_encoding() for this purpose. htmlspecialchars()/htmlentities() will not raise errors and return empty string for invalid char encoding by spec. Although you should validate char encoding at your input handling code, you may request to raise exception by additional option. It would be useful in some cases. e.g. Someone stored invalid UTF-8 string in your trusted database. Previous Comments: ------------------------------------------------------------------------ [2016-10-12 14:50:04] cmb@php.net > don't generate an error on log (that's the biggest problem) This can't be fixed, however, see bug #54109 and the tickets linked from there. > Apparently, then, returning an empty string is correct behavior > in the absence of that flag. ACK. Closing. ------------------------------------------------------------------------ [2015-08-31 13:18:44] antropik at gmail dot com (same problem on htmlentities) ------------------------------------------------------------------------ [2015-08-31 13:15:35] antropik at gmail dot com same problem with html_entity_decode error come with treatment of accent don't generate an error on log (that's the biggest problem) PHP 5.5.9-1ubuntu4.11 ------------------------------------------------------------------------ [2014-10-15 18:51:36] phpbugs at hypertwins dot org In my case, this does seem to be a character set problem: adding ENT_SUBSTITUTE to the "flags" parameter eliminates the blank results. This appears to be consistent with the documentation for that flag, which says it will "Replace invalid code unit sequences with a Unicode Replacement Character U+FFFD (UTF-8) or &#FFFD; (otherwise) instead of returning an empty string." Apparently, then, returning an empty string is correct behavior in the absence of that flag. ------------------------------------------------------------------------ [2014-09-17 19:35:02] pfenderd at bellsouth dot net I have been using PHP for 14 years and I have encountered similar problems wth the PHP script iterpreter that gets solved by rearranging the code statements without actually change the statements themselves. This seems to be one of those cases that will never be resolved. Since I found a coding solution that works for me and I cannot recreate the problem in a simple test case, then I guess that we should not waste any more time on this and close the bug report. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68031 -- Edit this bug report at https://bugs.php.net/bug.php?id=68031&edit=1

« previous php.bugs (#204651) next »