Bug #68567 [Csd]: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key

From: Date: Sun, 15 Oct 2017 18:43:42 +0000
Subject: Bug #68567 [Csd]: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211704@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68567&edit=1 ID: 68567 Updated by: bukka@php.net Reported by: johnhax at gmail dot com Summary: JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key Status: Closed Type: Bug Package: JSON related PHP Version: 5.6.3 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: I just fixed the JSON_PARTIAL_OUTPUT_ON_ERROR part in PHP-7.2. Please note that PHP-7.2 also has new options that allow ignoring or substituting UTF-8 invalid character which can be also used to address this. Previous Comments: ------------------------------------------------------------------------ [2017-10-15 18:38:55] bukka@php.net Automatic comment on behalf of bukka Revision: http://git.php.net/?p=php-src.git;a=commit;h=7c556c44a10bfc53c37295626e61bd99dc4f550c Log: Fix bug #68567 (JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key) ------------------------------------------------------------------------ [2017-10-15 18:37:48] bukka@php.net Automatic comment on behalf of bukka Revision: http://git.php.net/?p=php-src.git;a=commit;h=7c556c44a10bfc53c37295626e61bd99dc4f550c Log: Fix bug #68567 (JSON_PARTIAL_OUTPUT_ON_ERROR can result in JSON with null key) ------------------------------------------------------------------------ [2014-12-08 12:57:47] johnhax at gmail dot com Description: ------------ json_encode(array("\x80" => 1)) returns "{null: 1}" in PHP5.3 and PHP5.4. It's not a valid JSON, but at least we could use json_last_error() to catch it. Encoding recursion, INF/NAN or unsupported type results in a VALID json so that json_last_error() returns 0 (no error) and only emit E_WARNING. In fact, all JSON_ERROR_* constants are only for json_decode() until 5.3.3. From PHP 5.5, json_encode() does not emit E_WARNING anymore, JSON_ERROR_RECURSION/INF_OR_NAN/UNSUPPORTED_TYPE are added and json_last_error() may return them after json_encode(). (And it also possible return JSON_ERROR_DEPTH for the new third param of json_encode.) The problem is, there is NO way to be tolerant to these cases in PHP 5.5+! The undocumented option JSON_PARTIAL_OUTPUT_ON_ERROR is USELESS because json_last_error() only returns the last error, means there may be utf-8 error which results in invalid json. There are two possible solution: 1. When json_encode with JSON_PARTIAL_OUTPUT_ON_ERROR, encode array("\x80" => 1) to {"": 1} or {} (just drop the node) to ensure valid json output. 2. Implement new options like https://bugs.php.net/bug.php?id=65082 , and add more options to allow indicate how to treat recursion, Inf, NaN, unsupported type respectively. We'd better implement both, 1 for backward compatibility and 2 for drop unreliable json_last_error(). ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68567&edit=1

« previous php.bugs (#211704) next »