Bug #74482 [Nab]: Missing validation of date in DateTime::createFromFormat
Edit report at https://bugs.php.net/bug.php?id=74482&edit=1
ID: 74482
Updated by: heiglandreas@php.net
Reported by: spam at bugyik dot cz
Summary: Missing validation of date in
DateTime::createFromFormat
Status: Not a bug
Type: Bug
Package: Date/time related
Operating System: Linux
PHP Version: 7.1.4
Block user comment: N
Private report: N
New Comment:
If you're looking to validate the user-input then use DateTime::createFromFormat and check the
last error as suggested by php-bugs at allenjb dot me dot uk.
As it's an invalid Date you are providing "new DateTime()" will fail. When you want
to create a DateTime-Object from the provided date at all costs, use the factory-method
DateTime::createFromFormat.
Previous Comments:
------------------------------------------------------------------------
[2017-04-21 11:58:34] spam at bugyik dot cz
@heiglandreas: Yes of course, it's not a bug, it's a feature. So, there is two way to
create DateTime object from string with inconsistent behaviour. I forget, this is PHP :D
https://3v4l.org/v0IQb
> DateTime *assumes that you want to give a valid date*.
Sorry, but I'm using DateTime specially for validate user-input. I don't want to validate
myself if *2017-99-99* is valid date,
------------------------------------------------------------------------
[2017-04-21 11:38:36] heiglandreas@php.net
Nope. The date you provided actually is not invalid. DateTime *assumes that you want to give a valid
date*. As it's clearly not valid, DateTime tries to find a way to make it valid and also adds
an error to the log.
So when you want to break DateTime on purpose by passing it invalid parameters it's not a bug
in DateTime.
You are looking for a way to *validate* a date which is not something the DateTime-library is made
for. And as you are using a method that explicitly is named *create*FromFormat it can be assumed
that you want to get a DateTime-Object from the input and not want an exception to be thrownâ¦
------------------------------------------------------------------------
[2017-04-20 16:24:27] spam at bugyik dot cz
@allenjb: thanks for your suggestion, but I think this is only workaround, do you agree?
------------------------------------------------------------------------
[2017-04-20 15:06:17] php-bugs at allenjb dot me dot uk
DateTime has an internal warnings system it uses which you can use to detect invalid dates - see
DateTime::getLastErrors(): https://3v4l.org/8IBbL
------------------------------------------------------------------------
[2017-04-20 15:01:32] spam at bugyik dot cz
Description:
------------
I'm missing validation of date-time in DateTime::createFromFormat. The example below tells
more.
Test script:
---------------
<?php
var_dump(\DateTime::createFromFormat(\DateTime::RFC3339, '2017-99-99T08:51:13-03:00'));
Expected result:
----------------
some exception expected (like from new DateTime('bad-time'))
Actual result:
--------------
object(DateTime)#1 (3) {
["date"]=>
string(26) "2025-06-07 08:51:13.000000"
["timezone_type"]=>
int(1)
["timezone"]=>
string(6) "-03:00"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74482&edit=1
Thread (6 messages)