Bug #76664 [NEW]: Regression in URL rewrite when JavaScript href?

From: Date: Wed, 25 Jul 2018 16:56:41 +0000
Subject: Bug #76664 [NEW]: Regression in URL rewrite when JavaScript href?
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216455@lists.php.net to get a copy of this message
From: nicolas dot dermine at gmail dot com Operating system: linux PHP version: 7.2.8 Package: Output Control Bug Type: Bug Bug description:Regression in URL rewrite when JavaScript href? Description: ------------ We output some HTML markup inside a json_encoded string, with double quotes replaced by \u0022 (with the JSON_HEX_QUOT flag) the HTML markup contains a <a href="javascript:...> link which becomes <a href=\u0022javascript:...> when json_encoded we also use output_add_rewrite_var, and had no problem when using PHP 5.6 or PHP 7.0 (i.e .the parameter was not added, since this a JavaScript call, not a URL), but it seems since PHP 7.1.0 the URL parameter is added just before the first argument of the JavaScript function in the href attribute, resulting in a JavaScript error when it is clicked. Test script: --------------- <?php // tried this on https://3v4l.org/fmRvE output_add_rewrite_var('param_name', 'param_value'); ini_set('url_rewriter.tags', 'a=href'); echo '"<a href=\\u0022javascript:someFunc(\'some arg\')\\u0022>link 2</a>"'; Expected result: ---------------- Output for 5.6.30, 7.0.30 - 7.0.31 "<a href=\u0022javascript:someFunc('some arg')\u0022>link 2</a>" Actual result: -------------- Output for 7.1.0 - 7.3.0alpha4 "<a href=\u0022javascript:someFunc(?param_name=param_value'some arg')\u0022>link 2</a>" (the added ?param_name=param_value after the opening parenthesis causes a JavaScript error when the link is clicked.) -- Edit bug report at https://bugs.php.net/bug.php?id=76664&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76664&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76664&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76664&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=76664&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=76664&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=76664&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=76664&r=needscript Try newer version: https://bugs.php.net/fix.php?id=76664&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=76664&r=support Expected behavior: https://bugs.php.net/fix.php?id=76664&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=76664&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=76664&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=76664&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76664&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=76664&r=dst IIS Stability: https://bugs.php.net/fix.php?id=76664&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=76664&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=76664&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=76664&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=76664&r=mysqlcfg

« previous php.bugs (#216455) next »