Bug #75986 [Com]: JSON parser not following preposed RFC

From: Date: Tue, 20 Feb 2018 14:50:47 +0000
Subject: Bug #75986 [Com]: JSON parser not following preposed RFC
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214054@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75986&edit=1 ID: 75986 Comment by: welfordmartin at gmail dot com Reported by: welfordmartin at gmail dot com Summary: JSON parser not following preposed RFC Status: Not a bug Type: Bug Package: JSON related Operating System: Ubuntu Server 16.04 & Windows 10 PHP Version: 7.2.2 Block user comment: N Private report: N New Comment: Also since JSON stands for JavaScript Object Notation it would stand to reason that all of the Javascript engines currently in use do this correctly and don't escape things that are not listed as an escape. so everything else implementing it should do that as well. Previous Comments: ------------------------------------------------------------------------ [2018-02-20 14:50:43] nikic@php.net > Since backslash d (\d) is not one of the listed escapes allowed it should be evaluated to > unescaped (literal) "\" and "d"? as that is exactly what that standard. with > unescaped or escape one of this list it is explicitly a / meaning or. No, "\" may be followed **only** by the characters listed there. Note that the "unescaped" production explicitly excludes "\". > also, the UTF-8 encoded was tried after I mean to set it back to bracers before posting it in > the bug. Did you use both \\d and {} or \uXXXX escape sequences? If you still had \d the JSON would still be invalid. ------------------------------------------------------------------------ [2018-02-20 14:44:25] welfordmartin at gmail dot com you mean page 5. But even that says unescaped or escape one of %x22 / ; " quotation mark U+0022 %x5C / ; \ reverse solidus U+005C %x2F / ; / solidus U+002F %x62 / ; b backspace U+0008 %x66 / ; f form feed U+000C %x6E / ; n line feed U+000A %x72 / ; r carriage return U+000D %x74 / ; t tab U+0009 %x75 4HEXDIG ) ; uXXXX U+XXXX Since backslash d (\d) is not one of the listed escapes allowed it should be evaluated to unescaped (literal) "\" and "d"? as that is exactly what that standard. with unescaped or escape one of this list it is explicitly a / meaning or. also, the UTF-8 encoded was tried after I mean to set it back to bracers before posting it in the bug. ------------------------------------------------------------------------ [2018-02-20 14:22:13] nikic@php.net Yes, the freeformatter.com checker is non-conforming. Please see the "char" production on page 4 of the cited RFC 4627. For some more fun: http://seriot.ch/json/parsing.html Most JSON parsers are buggy in one way or another, so always take things with a grain of salt. To the best of our knowledge, the PHP 7 JSON parser is fully conforming (though the PHP 5 one is not). ------------------------------------------------------------------------ [2018-02-20 14:10:47] welfordmartin at gmail dot com The JSON is valid according to https://www.freeformatter.com/json-validator.html however, it fails on https://jsonlint.com/ and https://jsonformatter.curiousconcept.com/ while the latter says it's an invalid character at [Code 18, Structure 25] highlighting the UTF-8 chars as a problem so I think both of them are also not using a validator that does not conform to RFC4627 ------------------------------------------------------------------------ [2018-02-20 14:07:57] nikic@php.net Your JSON contains invalid escape sequences. \d is not valid JSON. \x7D is not valid JSON. The correct syntax is \\d and \u007D respectively. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75986 -- Edit this bug report at https://bugs.php.net/bug.php?id=75986&edit=1

« previous php.bugs (#214054) next »