Bug #73975 [NEW]: parse_url does not decode % escaping of username

From: Date: Mon, 23 Jan 2017 02:38:16 +0000
Subject: Bug #73975 [NEW]: parse_url does not decode % escaping of username
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206867@lists.php.net to get a copy of this message
From: trejkaz at trypticon dot org Operating system: macOS PHP version: 5.6.30 Package: URL related Bug Type: Bug Bug description:parse_url does not decode % escaping of username Description: ------------ The userinfo part of a URL can contain %-encoding for characters which otherwise would confuse a URL parser. Thus if your username or password contains, for instance, a @, you would be entering %40 into the URL instead. PHP's parse_url function does not perform decode this encoding, but returns the 'user' and 'pass' values with it as it was in the original URL. Alternatively, if the intent is that this function keeps the encoding in the values, this should be clearly stated in the documentation. It turns out that Drupal is calling this function, seemingly assuming that it is being completely decoded. Test script: --------------- <? var_dump(parse_url('https://user%40name:pass%40word@example.com')); ?> Expected result: ---------------- array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(9) "user@name" ["pass"]=> string(9) "pass@word" } Actual result: -------------- array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(11) "user%40name" ["pass"]=> string(11) "pass%40word" } -- Edit bug report at https://bugs.php.net/bug.php?id=73975&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73975&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73975&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73975&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73975&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73975&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73975&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73975&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73975&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73975&r=support Expected behavior: https://bugs.php.net/fix.php?id=73975&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73975&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73975&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73975&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73975&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73975&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73975&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73975&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73975&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73975&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73975&r=mysqlcfg

« previous php.bugs (#206867) next »