Req #75959 [Fbk->Opn]: Support a function to escape glob metacharacters

From: Date: Wed, 14 Feb 2018 11:44:16 +0000
Subject: Req #75959 [Fbk->Opn]: Support a function to escape glob metacharacters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213950@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75959&edit=1

 ID:                 75959
 Updated by:         requinix@php.net
 Reported by:        maggus dot staab+php at googlemail dot com
 Summary:            Support a function to escape glob metacharacters
-Status:             Feedback
+Status:             Open
 Type:               Feature/Change Request
-Package:            *General Issues
+Package:            Filesystem function related
 PHP Version:        7.0.27
 Block user comment: N
 Private report:     N

 New Comment:

According to glob(3) it sounds like extra backslashes aren't harmful. According to glob(7)
using a ^ (as in [^]) is defined to be undefined so maybe it should be escaped to be safe, but I do
see that quotemeta won't get ! or ~

The next step would be addcslashes. I'm sure POSIX PHP's glob uses the system's
glob(3) which has ?*[!]{~} as special - don't know how Windows PHP's glob works.

While {}s aren't special unless the GLOB_BRACE option is used, nevermind that GLOB_NOESCAPE
prevents escaping from doing anything at all, I think it would be best if the function worked like
quotemeta and preg_quote and simply escaped everything that could possibly be used. Speaking of, I
could see situations where periods and slashes could be special too, even though they're not
actually metacharacters.

Personally I would just use addcslashes depending on my use case, like to allow * ? but disallow
everything else. Listing the metacharacters in the glob docs would be helpful to that end. In fact
if it weren't for the fact that quotemeta exists, old as it is, I would say let's just
document what's special and tell people how to escape what they don't want.


Previous Comments:
------------------------------------------------------------------------
[2018-02-14 10:27:50] maggus dot staab+php at googlemail dot com

thx for the pointer.

this method does 90% of what I need, but is not exactly what I search.

e.g. glob() supports {} (curly-braces) but those are not escaped with this function.

additionally quotemeta() escapes the ^ character which is not a meta-char in the "glob"
sense.

------------------------------------------------------------------------
[2018-02-14 10:01:24] requinix@php.net

http://php.net/manual/en/function.quotemeta.php

------------------------------------------------------------------------
[2018-02-14 09:49:06] maggus dot staab+php at googlemail dot com

Description:
------------
Atm there is no api to escape glob patterns.

this makes glob() useless for cases in which dynamic (maybe even user-supplied contents will be
embedded into the glob pattern).

Test script:
---------------
$glob = 'hallo*lala'; // I want this string to match the literal '*' char 
glob(glob_quote($glob))



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75959&edit=1


Thread (6 messages)

« previous php.bugs (#213950) next »