Bug #68567 [Csd]: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key
| From: | bukka@php.net | Date: | Sun, 15 Oct 2017 18:43:42 +0000 |
| Subject: | Bug #68567 [Csd]: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211704@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68567&edit=1
ID: 68567
Updated by: bukka@php.net
Reported by: johnhax at gmail dot com
Summary: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with
null key
Status: Closed
Type: Bug
Package: JSON related
PHP Version: 5.6.3
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
I just fixed the JSON_PARTIAL_OUTPUT_ON_ERROR part in PHP-7.2. Please note that PHP-7.2 also has new
options that allow ignoring or substituting UTF-8 invalid character which can be also used to
address this.
Previous Comments:
------------------------------------------------------------------------
[2017-10-15 18:38:55] bukka@php.net
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7c556c44a10bfc53c37295626e61bd99dc4f550c
Log: Fix bug #68567 (JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key)
------------------------------------------------------------------------
[2017-10-15 18:37:48] bukka@php.net
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7c556c44a10bfc53c37295626e61bd99dc4f550c
Log: Fix bug #68567 (JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key)
------------------------------------------------------------------------
[2014-12-08 12:57:47] johnhax at gmail dot com
Description:
------------
json_encode(array("\x80" => 1)) returns "{null: 1}" in PHP5.3 and PHP5.4.
It's not a valid JSON, but at least we could use json_last_error() to catch it. Encoding
recursion, INF/NAN or unsupported type results in a VALID json so that json_last_error() returns 0
(no error) and only emit E_WARNING.
In fact, all JSON_ERROR_* constants are only for json_decode() until 5.3.3.
From PHP 5.5, json_encode() does not emit E_WARNING anymore,
JSON_ERROR_RECURSION/INF_OR_NAN/UNSUPPORTED_TYPE are added and json_last_error() may return them
after json_encode(). (And it also possible return JSON_ERROR_DEPTH for the new third param of
json_encode.)
The problem is, there is NO way to be tolerant to these cases in PHP 5.5+!
The undocumented option JSON_PARTIAL_OUTPUT_ON_ERROR is USELESS because json_last_error() only
returns the last error, means there may be utf-8 error which results in invalid json.
There are two possible solution:
1. When json_encode with JSON_PARTIAL_OUTPUT_ON_ERROR, encode array("\x80" => 1) to
{"": 1} or {} (just drop the node) to ensure valid json output.
2. Implement new options like https://bugs.php.net/bug.php?id=65082 , and add
more options to allow indicate how to treat recursion, Inf, NaN, unsupported type respectively.
We'd better implement both, 1 for backward compatibility and 2 for drop unreliable
json_last_error().
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68567&edit=1