Bug #75986 [Com]: JSON parser not following preposed RFC
| From: | welfordmartin at gmail dot com | Date: | Tue, 20 Feb 2018 14:44:26 +0000 |
| Subject: | Bug #75986 [Com]: JSON parser not following preposed RFC | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214052@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75986&edit=1
ID: 75986
Comment by: welfordmartin at gmail dot com
Reported by: welfordmartin at gmail dot com
Summary: JSON parser not following preposed RFC
Status: Not a bug
Type: Bug
Package: JSON related
Operating System: Ubuntu Server 16.04 & Windows 10
PHP Version: 7.2.2
Block user comment: N
Private report: N
New Comment:
you mean page 5.
But even that says unescaped or escape one of
%x22 / ; " quotation mark U+0022
%x5C / ; \ reverse solidus U+005C
%x2F / ; / solidus U+002F
%x62 / ; b backspace U+0008
%x66 / ; f form feed U+000C
%x6E / ; n line feed U+000A
%x72 / ; r carriage return U+000D
%x74 / ; t tab U+0009
%x75 4HEXDIG ) ; uXXXX U+XXXX
Since backslash d (\d) is not one of the listed escapes allowed it should be evaluated to unescaped
(literal) "\" and "d"? as that is exactly what that standard. with unescaped or
escape one of this list it is explicitly a / meaning or.
also, the UTF-8 encoded was tried after I mean to set it back to bracers before posting it in the
bug.
Previous Comments:
------------------------------------------------------------------------
[2018-02-20 14:22:13] nikic@php.net
Yes, the freeformatter.com checker is non-conforming. Please see the "char" production on
page 4 of the cited RFC 4627.
For some more fun: http://seriot.ch/json/parsing.html Most JSON parsers
are buggy in one way or another, so always take things with a grain of salt. To the best of our
knowledge, the PHP 7 JSON parser is fully conforming (though the PHP 5 one is not).
------------------------------------------------------------------------
[2018-02-20 14:10:47] welfordmartin at gmail dot com
The JSON is valid according to
https://www.freeformatter.com/json-validator.html
however, it fails on https://jsonlint.com/ and https://jsonformatter.curiousconcept.com/ while
the latter says it's an invalid character at [Code 18, Structure 25] highlighting the UTF-8
chars as a problem so I think both of them are also not using a validator that does not conform to
RFC4627
------------------------------------------------------------------------
[2018-02-20 14:07:57] nikic@php.net
Your JSON contains invalid escape sequences. \d is not valid JSON. \x7D is not valid JSON. The
correct syntax is \\d and \u007D respectively.
------------------------------------------------------------------------
[2018-02-20 14:00:41] welfordmartin at gmail dot com
Description:
------------
When using json_decode to decode a string value containing "{" or "}" the
validation fails and it does not produce an object this even happens when both are UTF-8 encoded
with "\x7B" and "\x7D" respectfully. both cases cause a
'JSON_ERROR_SYNTAX',
While the JSON code has been manually checked against the RFC4627 and it says standard C strings
well I can't believe I have to point this one out to you but using "{" and
"}" are both ASCII chars so valid in a string.
The JSON also parses correctly in Web Browsers both Chrome, Edge & IE parsers.
JSON Code used:
{
"defaultModel":"Campaign",
"routes" : {
"getCampaignsForWebsite":{
"scope" : "read_campaigns",
"api":{
"method" : "GET",
"uri" : "/campaign/\x7BdisplayType\x7D/\x7Bwebsite_id:\d+\x7D"
},
"perms":{
"module" : "website",
"requirement" : "read"
}
},
"getSingleCampaign":{
"scope" : "read_campaigns",
"api":{
"method" : "GET",
"uri" : "/campaign/\x7Bcampaign_id:\d+\x7D"
},
"perms":{
"module" : "campaign",
"requirement" : "read"
}
}
}
}
Test script:
---------------
$raw = file_get_contents("test.json");
$json = json_decode($raw, true);
switch (json_last_error()) {
case JSON_ERROR_NONE:
echo ' - No errors';
break;
case JSON_ERROR_DEPTH:
echo ' - Maximum stack depth exceeded';
break;
case JSON_ERROR_STATE_MISMATCH:
echo ' - Underflow or the modes mismatch';
break;
case JSON_ERROR_CTRL_CHAR:
echo ' - Unexpected control character found';
break;
case JSON_ERROR_SYNTAX:
echo ' - Syntax error, malformed JSON';
break;
case JSON_ERROR_UTF8:
echo ' - Malformed UTF-8 characters, possibly incorrectly encoded';
break;
default:
echo ' - Unknown error';
break;
}
Expected result:
----------------
I expect an array result when using assoc or a stdClass object when not.
Actual result:
--------------
Null and json_last_error results in JSON_ERROR_SYNTAX
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75986&edit=1