Bug #75163 [Opn->Nab]: filter_var with FILTER_SANITIZE_SPECIAL_CHARS is manipulating data
| From: | requinix@php.net | Date: | Wed, 06 Sep 2017 11:33:24 +0000 |
| Subject: | Bug #75163 [Opn->Nab]: filter_var with FILTER_SANITIZE_SPECIAL_CHARS is manipulating data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210972@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75163&edit=1
ID: 75163
Updated by: requinix@php.net
Reported by: itsursujit at gmail dot com
Summary: filter_var with FILTER_SANITIZE_SPECIAL_CHARS is
manipulating data
-Status: Open
+Status: Not a bug
Type: Bug
Package: Filter related
Operating System: Ubuntu
PHP Version: 5.6.31
Block user comment: N
Private report: N
New Comment:
' is not a URL-encoded ("percent-encoded") apostrophe. It is an HTML entity.
Previous Comments:
------------------------------------------------------------------------
[2017-09-06 11:07:47] itsursujit at gmail dot com
Description:
------------
I encountered this issue when I tried to sanitize urlencoded variables. Here are the steps with
expected and actual results:
Step 1: assign string to variable with encoded characters
$x="I've some comment";
Step 2: decode the variable using
urldecode()
$decoded=urldecode($x); //result: I've some comment;
echo $decoded;
EXPECTED RESULT: I've some comment
ACTUAL RESULT: I've some comment
Step 3: filter above decoded data and echo the result
echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS));
EXPECTED RESULT: I've some comment
ACTUAL RESULT: I've some comment
Step 4: filter above raw string and echo the result
echo trim(filter_var(stripslashes("I've some comment"),
FILTER_SANITIZE_SPECIAL_CHARS));
EXPECTED RESULT: I've some comment
ACTUAL RESULT: I've some comment
I think the Step 3 has some bug.
Test script:
---------------
<?php
$x="I've some comment";
$decoded=urldecode($x); //result: I've some comment;
echo $decoded; //result: I've some comment;
echo "\n";
echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS));
echo "\n";
echo trim(filter_var(stripslashes("I've some comment"),
FILTER_SANITIZE_SPECIAL_CHARS));
Expected result:
----------------
$x="I've some comment";
$decoded=urldecode($x); //result: I've some comment;
echo $decoded;
EXPECTED RESULT: I've some comment
echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS));
EXPECTED RESULT: I've some comment
echo trim(filter_var(stripslashes("I've some comment"),
FILTER_SANITIZE_SPECIAL_CHARS));
EXPECTED RESULT: I've some comment
Actual result:
--------------
$x="I've some comment";
$decoded=urldecode($x); //result: I've some comment;
echo $decoded;
ACTUAL RESULT: I've some comment
echo trim(filter_var(stripslashes($decoded), FILTER_SANITIZE_SPECIAL_CHARS));
ACTUAL RESULT: I've some comment
echo trim(filter_var(stripslashes("I've some comment"),
FILTER_SANITIZE_SPECIAL_CHARS));
ACTUAL RESULT: I've some comment
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75163&edit=1