Bug #74482 [Opn->Nab]: Missing validation of date in DateTime::createFromFormat

From: Date: Fri, 21 Apr 2017 11:38:41 +0000
Subject: Bug #74482 [Opn->Nab]: Missing validation of date in DateTime::createFromFormat
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208698@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74482&edit=1

 ID:                 74482
 Updated by:         heiglandreas@php.net
 Reported by:        spam at bugyik dot cz
 Summary:            Missing validation of date in
                     DateTime::createFromFormat
-Status:             Open
+Status:             Not a bug
 Type:               Bug
 Package:            Date/time related
 Operating System:   Linux
 PHP Version:        7.1.4
 Block user comment: N
 Private report:     N

 New Comment:

Nope. The date you provided actually is not invalid. DateTime *assumes that you want to give a valid
date*. As it's clearly not valid, DateTime tries to find a way to make it valid and also adds
an error to the log. 

So when you want to break DateTime on purpose by passing it invalid parameters it's not a bug
in DateTime.

You are looking for a way to *validate* a date which is not something the DateTime-library is made
for. And as you are using a method that explicitly is named *create*FromFormat it can be assumed
that you want to get a DateTime-Object from the input and not want an exception to be thrown…


Previous Comments:
------------------------------------------------------------------------
[2017-04-20 16:24:27] spam at bugyik dot cz

@allenjb: thanks for your suggestion, but I think this is only workaround, do you agree?

------------------------------------------------------------------------
[2017-04-20 15:06:17] php-bugs at allenjb dot me dot uk

DateTime has an internal warnings system it uses which you can use to detect invalid dates - see
DateTime::getLastErrors(): https://3v4l.org/8IBbL

------------------------------------------------------------------------
[2017-04-20 15:01:32] spam at bugyik dot cz

Description:
------------
I'm missing validation of date-time in DateTime::createFromFormat. The example below tells
more.

Test script:
---------------
<?php

var_dump(\DateTime::createFromFormat(\DateTime::RFC3339, '2017-99-99T08:51:13-03:00'));

Expected result:
----------------
some exception expected (like from new DateTime('bad-time'))

Actual result:
--------------
object(DateTime)#1 (3) {
  ["date"]=>
  string(26) "2025-06-07 08:51:13.000000"
  ["timezone_type"]=>
  int(1)
  ["timezone"]=>
  string(6) "-03:00"
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74482&edit=1


Thread (6 messages)

« previous php.bugs (#208698) next »