Bug #42718 [Asn->Opn]: FILTER_UNSAFE_RAW not applied when configured as default filter, even with flags

From: Date: Tue, 24 Oct 2017 07:30:22 +0000
Subject: Bug #42718 [Asn->Opn]: FILTER_UNSAFE_RAW not applied when configured as default filter, even with flags
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212080@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42718&edit=1

 ID:                 42718
 Updated by:         kalle@php.net
 Reported by:        arnaud dot lb at gmail dot com
 Summary:            FILTER_UNSAFE_RAW not applied when configured as
                     default filter, even with flags
-Status:             Assigned
+Status:             Open
 Type:               Bug
 Package:            Filter related
 Operating System:   *
 PHP Version:        5.*, 6CVS (2009-04-30)
-Assigned To:        pajoye
+Assigned To:        
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2010-04-05 18:21:03] rasmus@php.net

We should figure out what we want here.  Do we want to allow default flags to be 
applied with the unsafe_raw filter or not?

------------------------------------------------------------------------
[2008-12-06 19:20:34] pajoye@php.net

Yes, revert was the best option for now.

I will dig into it on Monday and re read the discussions about that (there was some discussions
about this whole thing when we added filter to core).


------------------------------------------------------------------------
[2008-12-06 19:17:09] lbarnaud@php.net

> That's wrong

This is exactly what you said one year ago, just before it was demonstrated that FILTER_UNSAFE_RAW
actually does something (according to documentation, code, and examples), and the bug has been
assigned to you.

That said, I'm not rejecting the fault on anyone, and the important is to revert, which is
done.


------------------------------------------------------------------------
[2008-12-06 18:25:20] pajoye@php.net

ooch.

I did not catch in this bug before, but there is a major misunderstanding in the first comment.

"The unsafe_raw filter does nothing by default, but it 
can "optionally strip or encode special characters", and it is the 
only filter which is able to do that without doing any other 
filtering."

That's wrong. UNSAFE_RAW, the key word here is RAW. It means that the data is returned
unfiltered, without flag, nothing, nada. If this behavior has been changed then please revert it.

I did not check if it is present in 5.2.7 (it seems to be, as said in this report or another), that
may require a quick fix release (Ilia?).

------------------------------------------------------------------------
[2008-12-06 17:52:37] lbarnaud@php.net

All my apologizes for this broken fix.

A quick workaround for 5.2.7 users is to add the following in the php.ini:
filter.default_flags=0

Scott has reverted this and this bug is not present in CVS.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=42718


--
Edit this bug report at https://bugs.php.net/bug.php?id=42718&edit=1


Thread (19 messages)

« previous php.bugs (#212080) next »