Bug #73595 [Opn->Dup]: parse_url fails if passing '#' in passwd
| From: | requinix@php.net | Date: | Wed, 23 Nov 2016 20:38:03 +0000 |
| Subject: | Bug #73595 [Opn->Dup]: parse_url fails if passing '#' in passwd | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205585@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73595&edit=1
ID: 73595
Updated by: requinix@php.net
Reported by: dakusan at castledragmire dot com
Summary: parse_url fails if passing '#' in passwd
-Status: Open
+Status: Duplicate
Type: Bug
Package: URL related
Operating System: Linux
PHP Version: 5.6.28
Block user comment: N
Private report: N
New Comment:
Allowing # like that was a bug - security bug, no less - which is why it was fixed. You should be
urlencode()ing the password.
See also bug #73500
Previous Comments:
------------------------------------------------------------------------
[2016-11-23 20:24:54] dakusan at castledragmire dot com
Description:
------------
I believe this happened in commit "f0f68c72744a42a1c376a832dd01c012c0929e88". The reason I
am considering this a bug is that it broke expected behavior in a minor version change.
Test script:
---------------
var_dump(parse_url('mysql://username:xxx#xxx@localhost/databasename'));
Expected result:
----------------
array(5) { ["scheme"]=> string(5) "mysql" ["host"]=> string(9)
"localhost" ["user"]=> string(8) "username" ["pass"]=>
string(7) "xxx#xxx" ["path"]=> string(13) "/databasename" }
Actual result:
--------------
FALSE
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73595&edit=1