Bug #73054 [Csd]: default option ignored when object passed to int filter

From: Date: Sun, 04 Jun 2017 01:38:37 +0000
Subject: Bug #73054 [Csd]: default option ignored when object passed to int filter
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209378@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73054&edit=1

 ID:                 73054
 Updated by:         yohgaki@php.net
 Reported by:        dormilich at netscape dot net
 Summary:            default option ignored when object passed to int
                     filter
 Status:             Closed
 Type:               Bug
 Package:            Filter related
 Operating System:   Mac OS X 10.11.6
 PHP Version:        5.6.25
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

I came across this bug fix bug.

Currently, VALIDATE filter returns default values for _invalid_ parameter value/type.

Sanitizing filter may ignore _invalid_ parameter value/type.
However, validation filter must not ignore _invalid_ parameter and must not use default value. It
should treat invalid parameters as error.

BTW, ignoring invalid values is now considered as security vulnerability.
See OWASP TOP 10 2017 edition RC. (A7 Insufficient Attack Protection)


Previous Comments:
------------------------------------------------------------------------
[2016-10-17 10:08:28] bwoebi@php.net

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=23e721fc9303dd7423f989f6ff360cdff74aeca1
Log: Fix #73054: default option ignored when object passed to int filter

------------------------------------------------------------------------
[2016-09-09 12:52:30] cmb@php.net

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=23e721fc9303dd7423f989f6ff360cdff74aeca1
Log: Fix #73054: default option ignored when object passed to int filter

------------------------------------------------------------------------
[2016-09-09 10:23:16] cmb@php.net

I can confirm both issues: <https://3v4l.org/mAtsv> and
<https://3v4l.org/qEUtH>.

The first issue has been introduced with the fix for bug #49274,
where the function bails out too early thereby ignoring any
default value.

The second issue is actually a duplicate of bug #67167, which has
been fixed (in this regard) only as of PHP 7. The fix should be
backported to PHP 5.6.

------------------------------------------------------------------------
[2016-09-09 08:46:28] dormilich at netscape dot net

Description:
------------
When any object is passed through filter_var() with the FILTER_VALIDATE_INT filter and a default
option the result is always boolean false instead of the default value. 

Second, the FILTER_NULL_ON_FAILURE flag also shows no effect on passed objects.

Test script:
---------------
<?php
$id = filter_var(new stdClass, FILTER_VALIDATE_INT, [
    'options' => ['default' => 2],
]);
var_dump($id);

Expected result:
----------------
int(2)

Actual result:
--------------
bool(false)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73054&edit=1


Thread (9 messages)

« previous php.bugs (#209378) next »