Bug #73500 [Opn->Wfx]: parse_url behaviour changed between 7.0.12 and 7.0.13 when pw begins with #
| From: | ab@php.net | Date: | Sun, 13 Nov 2016 16:07:47 +0000 |
| Subject: | Bug #73500 [Opn->Wfx]: parse_url behaviour changed between 7.0.12 and 7.0.13 when pw begins with # | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205337@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73500&edit=1
ID: 73500
Updated by: ab@php.net
Reported by: max at substrakt dot com
Summary: parse_url behaviour changed between 7.0.12 and
7.0.13 when pw begins with #
-Status: Open
+Status: Wont fix
Type: Bug
Package: URL related
Operating System: Ubuntu Linux
PHP Version: 7.0.13
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-11-11 15:22:34] nikic@php.net
Just like for other parts of a URI, it is necessary to URL-encode passwords (for example, using the
urlencode() function). The "#" in your password should be "%23" instead.
As bug #73192, which resulted in this change, is classified as a security bug, I don't think
we'll take further action here.
------------------------------------------------------------------------
[2016-11-11 15:08:23] max at substrakt dot com
Description:
------------
When running the following code on PHP 7.0.12 and 7.0.13, a different result is returned.
In the later version, the user and pass attributes are missing. This _only_ occurs when the first
character of the password is # (hash/pound). Strong passwords can often include the # symbol so this
is unexpected behaviour.
I've not raised a bug in PHP before, please let me know if you need further information to
resolve this!
Test script:
---------------
<?php
$url =
"mysql://user:#fhdsjfghjdf@host.eu-west-1.rds.amazonaws.com:3306/database_name";
var_dump(parse_url($url));
Expected result:
----------------
array(6) {
["scheme"]=>
string(5) "mysql"
["host"]=>
string(32) "host.eu-west-1.rds.amazonaws.com"
["port"]=>
int(3306)
["user"]=>
string(4) "user"
["pass"]=>
string(12) "#fhdsjfghjdf"
["path"]=>
string(14) "/database_name"
}
Actual result:
--------------
array(3) {
["scheme"]=>
string(5) "mysql"
["host"]=>
string(4) "user"
["fragment"]=>
string(63) "fhdsjfghjdf@host.eu-west-1.rds.amazonaws.com:3306/database_name"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73500&edit=1