Bug #74036 [Opn]: createTextNode() does not handle binary data

From: Date: Thu, 02 Feb 2017 18:10:54 +0000
Subject: Bug #74036 [Opn]: createTextNode() does not handle binary data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207134@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74036&edit=1

 ID:                 74036
 User updated by:    judge2005 at gmail dot com
 Reported by:        judge2005 at gmail dot com
 Summary:            createTextNode() does not handle binary data
 Status:             Open
 Type:               Bug
 Package:            DOM XML related
 Operating System:   RHEL 7
 PHP Version:        7.0.15
 Block user comment: N
 Private report:     N

 New Comment:

It is a tricky one for me. The input to the method is arbitrary as it is externally generated. If
everyone who uses the createTextNode() method is forced to sanitize the input, it kills some of the
benefit of createTextNode(), which is that it sanitizes most things, just not low ascii values.
Everyone would have to add code to perform the sanitization. In addition - in this case - the call
is in a third party library (PHPUnit to be precise). I have submitted a bug report to them too,
however there may be many third-party libraries that also use this method. At a minimum the
documentation should point out this problem and maybe point the reader at createCDATASection (though
I haven't tried that, so I don't know if it handles this). But given that it already
performs sanitization on most of the input, it is arguable that it should handle this case too.


Previous Comments:
------------------------------------------------------------------------
[2017-02-02 17:55:01] requinix@php.net

I don't think this is a bug. Though DOM 3 doesn't say much, from what I can gather
createTextNode should not try to sanitize the text input. And though &"'<> will
be escaped during serialization, according to context, that's all and it's up to the
developer to not do things like use control characters.

Testing with Javascript in Chrome does the same thing: the characters are left as-is and not
escaped. Adding it to an XML document, serializing to a string, then parsing the string results in a
parse error.

And the bug system didn't strip them. The characters are there, your browser is just not
rendering them as anything.

------------------------------------------------------------------------
[2017-02-02 17:10:36] judge2005 at gmail dot com

Looks like your bug report system strips out the binary. The additional characters were ETX, EOT and
DC4

------------------------------------------------------------------------
[2017-02-02 17:08:20] judge2005 at gmail dot com

Description:
------------
If binary data is passed to createTextNode() it can cause invalid XML to be generated.

Test script:
---------------
<?php
$document  = new DOMDocument('1.0', 'UTF-8');
$document->formatOutput = true;

$root = $document->createElement('example');
$document->appendChild($root);

$example = $document->createTextNode("PK");	
$root->appendChild($example);

echo $document->saveXML();

Actual result:
--------------
<?xml version="1.0" encoding="UTF-8"?>
<example>PK</example>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74036&edit=1


Thread (4 messages)

« previous php.bugs (#207134) next »