Bug #73595 [Opn->Dup]: parse_url fails if passing '#' in passwd

From: Date: Wed, 23 Nov 2016 20:38:03 +0000
Subject: Bug #73595 [Opn->Dup]: parse_url fails if passing '#' in passwd
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205585@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73595&edit=1 ID: 73595 Updated by: requinix@php.net Reported by: dakusan at castledragmire dot com Summary: parse_url fails if passing '#' in passwd -Status: Open +Status: Duplicate Type: Bug Package: URL related Operating System: Linux PHP Version: 5.6.28 Block user comment: N Private report: N New Comment: Allowing # like that was a bug - security bug, no less - which is why it was fixed. You should be urlencode()ing the password. See also bug #73500 Previous Comments: ------------------------------------------------------------------------ [2016-11-23 20:24:54] dakusan at castledragmire dot com Description: ------------ I believe this happened in commit "f0f68c72744a42a1c376a832dd01c012c0929e88". The reason I am considering this a bug is that it broke expected behavior in a minor version change. Test script: --------------- var_dump(parse_url('mysql://username:xxx#xxx@localhost/databasename')); Expected result: ---------------- array(5) { ["scheme"]=> string(5) "mysql" ["host"]=> string(9) "localhost" ["user"]=> string(8) "username" ["pass"]=> string(7) "xxx#xxx" ["path"]=> string(13) "/databasename" } Actual result: -------------- FALSE ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73595&edit=1

« previous php.bugs (#205585) next »