Edit report at https://bugs.php.net/bug.php?id=76160&edit=1
ID: 76160
Comment by: deepdiver at owncloud dot com
Reported by: deepdiver at owncloud dot com
Summary: Font not loaded if path holds semi collon
Status: Open
Type: Bug
Package: GD related
Operating System: Debian Linux
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
<igony>Always a pleasure to see how polite and welcoming an open source community can be
...</igony>
I fixed that meanwhile ... still I consider this a bug.
Previous Comments:
------------------------------------------------------------------------
[2018-03-29 10:09:40] spam2 at rhsoft dot net
> The root directory was computed based on ci config
> parameters which had the semi colon in place
well fix that crap, php runs on different operating systems and not all of them allows every char
static function NormalizeFilename(string $filename): string
{
static $allowed_chars;
if(empty($allowed_chars))
{
$allowed_chars = array_flip(str_split('0123456789abcdefghijklmnopqrstuvwxyz_.-'));
}
$filename = trim(strtolower($filename));
$filename = str_replace([chr(246),chr(214),chr(196),chr(228),chr(252),chr(220),chr(223)],
['oe','oe','ae','ae','ue','ue','ss'],
$filename);
$input_array = str_split(str_replace("\0", '', $filename));
foreach($input_array as $key=>$char)
{
if(!isset($allowed_chars[$char]))
{
$input_array[$key] = '_';
}
}
$filename = implode('', $input_array);
while(strpos($filename, '..') !== false)
{
$filename = str_replace('..', '.', $filename);
}
while(strpos($filename, '__') !== false)
{
$filename = str_replace('__', '_', $filename);
}
$filename = str_replace('.php.', '.', $filename);
return $filename;
}
------------------------------------------------------------------------
[2018-03-29 10:03:18] deepddiver at owncloud dot com
Well this is only the simplistic test code.
In real life I got hit by this in a continuous integration environment where the semi colon was
part of the root directory.
The root directory was computed based on ci config parameters which had the semi colon in place.
It took quite some time to find out about this .... unnecessarily
Never the less I'd expect that the given path is taken as is and not processed in a path list
where the semi colon is used as separator..
------------------------------------------------------------------------
[2018-03-29 09:58:27] spam2 at rhsoft dot net
don't get me wrong but using special chars in folder and filenames on webservers is in 2018
still dumb for the same reasons it was 1998 and that won't change in 2028 that much
------------------------------------------------------------------------
[2018-03-29 09:48:53] deepdiver at owncloud dot com
Description:
------------
As soon as a semi-collon is in the path the font can no longer be loaded.
Tested with php 5.6 as well as php 7.2
Test script:
---------------
<?php
$fontFile = __DIR__ . '/fonts/foo;bar/OpenSans-Regular.ttf';
$image = imagecreate(128, 128);
$textColor = imagecolorallocate($image, 0, 0, 0);
imagettftext($image, 18, 0, 0, 0, $textColor, $fontFile, 'lorem');
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76160&edit=1