Bug #74482 [Nab]: Missing validation of date in DateTime::createFromFormat

From: Date: Fri, 21 Apr 2017 11:58:36 +0000
Subject: Bug #74482 [Nab]: Missing validation of date in DateTime::createFromFormat
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208699@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74482&edit=1 ID: 74482 User updated by: spam at bugyik dot cz Reported by: spam at bugyik dot cz Summary: Missing validation of date in DateTime::createFromFormat Status: Not a bug Type: Bug Package: Date/time related Operating System: Linux PHP Version: 7.1.4 Block user comment: N Private report: N New Comment: @heiglandreas: Yes of course, it's not a bug, it's a feature. So, there is two way to create DateTime object from string with inconsistent behaviour. I forget, this is PHP :D https://3v4l.org/v0IQb > DateTime *assumes that you want to give a valid date*. Sorry, but I'm using DateTime specially for validate user-input. I don't want to validate myself if *2017-99-99* is valid date, Previous Comments: ------------------------------------------------------------------------ [2017-04-21 11:38:36] heiglandreas@php.net Nope. The date you provided actually is not invalid. DateTime *assumes that you want to give a valid date*. As it's clearly not valid, DateTime tries to find a way to make it valid and also adds an error to the log. So when you want to break DateTime on purpose by passing it invalid parameters it's not a bug in DateTime. You are looking for a way to *validate* a date which is not something the DateTime-library is made for. And as you are using a method that explicitly is named *create*FromFormat it can be assumed that you want to get a DateTime-Object from the input and not want an exception to be thrown… ------------------------------------------------------------------------ [2017-04-20 16:24:27] spam at bugyik dot cz @allenjb: thanks for your suggestion, but I think this is only workaround, do you agree? ------------------------------------------------------------------------ [2017-04-20 15:06:17] php-bugs at allenjb dot me dot uk DateTime has an internal warnings system it uses which you can use to detect invalid dates - see DateTime::getLastErrors(): https://3v4l.org/8IBbL ------------------------------------------------------------------------ [2017-04-20 15:01:32] spam at bugyik dot cz Description: ------------ I'm missing validation of date-time in DateTime::createFromFormat. The example below tells more. Test script: --------------- <?php var_dump(\DateTime::createFromFormat(\DateTime::RFC3339, '2017-99-99T08:51:13-03:00')); Expected result: ---------------- some exception expected (like from new DateTime('bad-time')) Actual result: -------------- object(DateTime)#1 (3) { ["date"]=> string(26) "2025-06-07 08:51:13.000000" ["timezone_type"]=> int(1) ["timezone"]=> string(6) "-03:00" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74482&edit=1

« previous php.bugs (#208699) next »