Bug #73975 [Ver]: parse_url does not decode % escaping of username
| From: | nikic@php.net | Date: | Mon, 23 Jan 2017 11:44:08 +0000 |
| Subject: | Bug #73975 [Ver]: parse_url does not decode % escaping of username | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206879@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73975&edit=1
ID: 73975
Updated by: nikic@php.net
Reported by: trejkaz at trypticon dot org
Summary: parse_url does not decode % escaping of username
Status: Verified
Type: Bug
Package: URL related
Operating System: macOS
PHP Version: 5.6.30
Block user comment: N
Private report: N
New Comment:
It does not look like any component of the URL is url-decoded by parse_url(). While I personally
think that parse_url() *ought* to be doing this, changing it at this point would be
counter-productive, as client code would have to conditionally decode the result (rather than always
decode it), leading to more brittle code.
Previous Comments:
------------------------------------------------------------------------
[2017-01-23 11:35:21] cmb@php.net
Confirmed: <https://3v4l.org/W8DWh>.
------------------------------------------------------------------------
[2017-01-23 02:38:11] trejkaz at trypticon dot org
Description:
------------
The userinfo part of a URL can contain %-encoding for characters which otherwise would confuse a URL
parser.
Thus if your username or password contains, for instance, a @, you would be entering %40 into the
URL instead.
PHP's parse_url function does not perform decode this encoding, but returns the
'user' and 'pass' values with it as it was in the original URL.
Alternatively, if the intent is that this function keeps the encoding in the values, this should be
clearly stated in the documentation. It turns out that Drupal is calling this function, seemingly
assuming that it is being completely decoded.
Test script:
---------------
<?
var_dump(parse_url('https://user%40name:pass%40word@example.com'));
?>
Expected result:
----------------
array(4) {
["scheme"]=>
string(5) "https"
["host"]=>
string(11) "example.com"
["user"]=>
string(9) "user@name"
["pass"]=>
string(9) "pass@word"
}
Actual result:
--------------
array(4) {
["scheme"]=>
string(5) "https"
["host"]=>
string(11) "example.com"
["user"]=>
string(11) "user%40name"
["pass"]=>
string(11) "pass%40word"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73975&edit=1