Bug #75746 [Fbk->Csd]: empty string is (wrongly) accepted as valid json

From: Date: Sat, 30 Dec 2017 02:17:16 +0000
Subject: Bug #75746 [Fbk->Csd]: empty string is (wrongly) accepted as valid json
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213324@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75746&edit=1 ID: 75746 User updated by: php at richardneill dot org Reported by: php at richardneill dot org Summary: empty string is (wrongly) accepted as valid json -Status: Feedback +Status: Closed Type: Bug Package: JSON related Operating System: Linux PHP Version: 7.2.0 Block user comment: N Private report: N New Comment: Oh bother. It turns out that this particular machine has got both mod-php7 and mod-php5 on it. And while /usr/bin/php gives precedence to 7.x, apache gives precendence to 5.x. So yes, it's legacy behaviour in 5, and working correctly in 7, and while I thought I was running 7, I actually wasn't. Please close this bug as E_REPORTER_IS_A_DOZY_TWIT. Sorry to have filed a dud report. Previous Comments: ------------------------------------------------------------------------ [2017-12-30 01:32:27] danack@php.net I think the fix was applied to 7.0+, not to the 5 series: https://3v4l.org/0MCkJ Changing the code slightly to be more explicit: $checkme = ''; json_decode($checkme); if (json_last_error() === JSON_ERROR_NONE){ echo "No error."; }else{ echo "error detected of : " . json_last_error() . " " . json_last_error_msg(); } Gives the output: Output for 7.0.0 - 7.2.0 error detected of : 4 Syntax error Output for 5.6.0 - 5.6.30, hhvm-3.18.5 - 3.22.0 No error. Can you confirm it's actually ok in 7, and just has the legacy behaviour in 5? ------------------------------------------------------------------------ [2017-12-30 00:51:11] php at richardneill dot org Description: ------------ In order to validate whether a given string is legitimate JSON, the documentation at: http://php.net/manual/en/function.json-decode.php suggests that we run it through json_decode() and then check that json_last_error() is JSON_ERROR_NONE. However, when the string is empty, json_last_error() is not set. The empty string is not syntactically valid as json. Test script: --------------- $checkme = ''; json_decode($checkme); if (json_last_error() === JSON_ERROR_NONE){ echo "OK"; }else{ echo "FAIL"; } #This should result in "FAIL", #but it gives "OK", wrongly imho. Expected result: ---------------- json_decode(''); should set json_last_error(). Actual result: -------------- [Note: this seems to be very similar to the same issue in bugs 54484 and 68938, both of which were fixed and closed on the PHP 5 series] ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75746&edit=1

« previous php.bugs (#213324) next »