Bug #73975 [NEW]: parse_url does not decode % escaping of username
| From: | trejkaz at trypticon dot org | Date: | Mon, 23 Jan 2017 02:38:16 +0000 |
| Subject: | Bug #73975 [NEW]: parse_url does not decode % escaping of username | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-206867@lists.php.net to get a copy of this message | ||
From: trejkaz at trypticon dot org
Operating system: macOS
PHP version: 5.6.30
Package: URL related
Bug Type: Bug
Bug description:parse_url does not decode % escaping of username
Description:
------------
The userinfo part of a URL can contain %-encoding for characters which
otherwise would confuse a URL parser.
Thus if your username or password contains, for instance, a @, you would
be entering %40 into the URL instead.
PHP's parse_url function does not perform decode this encoding, but
returns the 'user' and 'pass' values with it as it was in the original
URL.
Alternatively, if the intent is that this function keeps the encoding in
the values, this should be clearly stated in the documentation. It turns
out that Drupal is calling this function, seemingly assuming that it is
being completely decoded.
Test script:
---------------
<?
var_dump(parse_url('https://user%40name:pass%40word@example.com'));
?>
Expected result:
----------------
array(4) {
["scheme"]=>
string(5) "https"
["host"]=>
string(11) "example.com"
["user"]=>
string(9) "user@name"
["pass"]=>
string(9) "pass@word"
}
Actual result:
--------------
array(4) {
["scheme"]=>
string(5) "https"
["host"]=>
string(11) "example.com"
["user"]=>
string(11) "user%40name"
["pass"]=>
string(11) "pass%40word"
}
--
Edit bug report at https://bugs.php.net/bug.php?id=73975&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73975&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73975&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73975&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73975&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73975&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73975&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73975&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73975&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73975&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73975&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73975&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73975&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73975&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73975&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73975&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73975&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73975&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73975&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73975&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73975&r=mysqlcfg