Bug #73054 [ReO->Asn]: default option ignored when object passed to int filter
Edit report at https://bugs.php.net/bug.php?id=73054&edit=1
ID: 73054
Updated by: kalle@php.net
Reported by: dormilich at netscape dot net
Summary: default option ignored when object passed to int
filter
-Status: Re-Opened
+Status: Assigned
Type: Bug
Package: Filter related
Operating System: Mac OS X 10.11.6
PHP Version: 5.6.25
Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-06-07 22:45:06] yohgaki@php.net
I've proposed fix already.
https://wiki.php.net/rfc/add_validate_functions_to_filter
The patch behaves as it should. This RFC is declined, though.
I shall propose the RFC again, since current filter module lacks the most important
filter/validation. i.e. String filter/validation.
We may be better to have distinguished API for validation and sanitizing. i.e. New module and new
API for these.
------------------------------------------------------------------------
[2017-06-07 22:10:06] yohgaki@php.net
Thanks, I'm responsible for this then.
New OWASP TOP 10 considers current behavior as vulnerability.
I'll submit change proposal.
------------------------------------------------------------------------
[2017-06-06 15:13:03] cmb@php.net
> Currently, VALIDATE filter returns default values for _invalid_
> parameter value/type.
Indeed, and this behavior is documented[1]:
| When default is set to option, default's value is used if value
| is not validated.
This part of the documentation has been committed by you, by the
way, see <http://svn.php.net/viewvc?view=revision&revision=331940>.
Anyhow, this bug fix only changes the behavior with regard to
objects to be consistent with the behavior of otherwise invalid
values, see <https://3v4l.org/IVO7g>, so please open a
new ticket
if you think the behavior is erroneous.
[1] <http://php.net/manual/en/filter.filters.validate.php>
------------------------------------------------------------------------
[2017-06-04 01:38:35] yohgaki@php.net
I came across this bug fix bug.
Currently, VALIDATE filter returns default values for _invalid_ parameter value/type.
Sanitizing filter may ignore _invalid_ parameter value/type.
However, validation filter must not ignore _invalid_ parameter and must not use default value. It
should treat invalid parameters as error.
BTW, ignoring invalid values is now considered as security vulnerability.
See OWASP TOP 10 2017 edition RC. (A7 Insufficient Attack Protection)
------------------------------------------------------------------------
[2016-10-17 10:08:28] bwoebi@php.net
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=23e721fc9303dd7423f989f6ff360cdff74aeca1
Log: Fix #73054: default option ignored when object passed to int filter
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73054
--
Edit this bug report at https://bugs.php.net/bug.php?id=73054&edit=1
Thread (9 messages)