Bug #64948 [Com]: FILTER_VALIDATE_URL does not see urls with underscores as valid URLs.

From: Date: Mon, 15 Oct 2018 15:22:11 +0000
Subject: Bug #64948 [Com]: FILTER_VALIDATE_URL does not see urls with underscores as valid URLs.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217573@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64948&edit=1

 ID:                 64948
 Comment by:         spam2 at rhsoft dot net
 Reported by:        neclimdul at gmail dot com
 Summary:            FILTER_VALIDATE_URL does not see urls with
                     underscores as valid URLs.
 Status:             Open
 Type:               Bug
 Package:            Filter related
 Operating System:   Ubuntu
 PHP Version:        5.4.15
 Block user comment: N
 Private report:     N

 New Comment:

it is that simple - there are RFC's covering that the underscore is not allowed and there are
clients which behave completly weird if you insist using them

if i could only have the lifetime a few people of me wasted because they never remember things
lonmger than a few mnoths leading to sit again with a local development URL containing and
underscore and wasting hours of debugging why things don#t work relieable in MSIE and so on

just don't se underscores - it's that simple


Previous Comments:
------------------------------------------------------------------------
[2018-10-15 15:13:48] neclimdul at gmail dot com

Woooh blast from the past.

> Definitely won't fix? parse_url() handles underscores quite nicely.

Its been so long but it feels like that discrepancy(that parse_url is fine with underscores and
filter_var isn't) was connected to me reporting this. Like, some tool used directory names to
automate subdomains and parse_url, browsers, and everything else had been happy then a stray
filter_var with VALIDATE_URL killed it all. So... not really nicely.

> you MUST NOT use underscores in your DNS names - it's that simple

I don't think it is that simple. Like aharvey in his initial response, this is spread out over
lots of RFCs and muddy implementation so I think we need to be 100% clear and documented in why this
works the way it does.

First I want to make the DNS argument 100% clear. DNS hostnames disallow but DNS allows (and
requires) names with underscores in some cases. This makes it more clear than I could here. http://domainkeys.sourceforge.net/underscore.html
http://ietf.org/rfc/rfc2782.txt

If the argument is that URL authorities should be A & AAAA record hostnames, you probably have a
point and my RFC lawyering is not up to arguing against it but DNS would not be the reason,
URL's would.

Second, the point from the initial bug report is that these URLs can happen in reality. The fact is
that support for them is more in the "it works" category then the "it
doesn't" with this implementation mostly just falling in with IE.

While I appreciate filter_var's adherence to RFC's, this is a case where real world and
RFC's have a disconnect and at the least should be clearly documented to people stumbling into
this because as Luke pointed out, its not even consistent in this language.

------------------------------------------------------------------------
[2018-10-15 14:30:09] spam2 at rhsoft dot net

you MUST NOT use underscores in your DNS names - it's that simple

------------------------------------------------------------------------
[2018-10-15 13:47:04] luke at reviews dot co dot uk

Definitely won't fix? parse_url() handles underscores quite nicely.

------------------------------------------------------------------------
[2015-08-21 17:14:03] rich at social5 dot com

The very Stack Overflow link aharvey@php.net referenced seems to suggest that FILTER_VALIDATE_URL
*should* allow underscores, does it not?

Regardless, ultimately, FILTER_VALIDATE_URL is used "in the wild" to verify whether or not
accessing a URL will load a web resource.  There certainly *are* many sites that use underscores in
both the main domain as well as the subdomain.  Regardless of the "lawyer material" (which
one could argue is in favor of "allowing" underscores, anyway), doesn't it make sense
to have FILTER_VALIDATE_URL reflect URLs that are actually used?

This means that FILTER_VALIDATE_URL is useless for us since it causes our system to reject customers
that happen to have an underscore in their URL.  Unless this bug is fixed, we'll have to
implement a separate solution that will allow the underscore-laden URLs.

This doesn't sound like the best solution to me.  Wouldn't you agree?

------------------------------------------------------------------------
[2013-05-30 17:46:40] aharvey@php.net

This is a tricky one. I think the current behaviour is technically correct here, 
but I don't particularly want to summarily close this either.

Technically speaking, host names can't include underscores. 
http://stackoverflow.com/a/2183140 links to the
various RFCs that define this — 
domain names (such as those used in SRV records) can contain underscores, but 
host names have a more restrictive character set.

That said, RFC 3986 (which is presumably what a URL validation routine is 
ultimately beholden to) is specified more loosely to cover non-DNS name 
registries. Hosts are reg-name elements there, which allows percent encoded 
characters, hyphens, dots, underscores, tildes, and a range of characters 
defined as sub-delims.

Given that underscores do have implementation issues in the wild (IE's cookie 
issues, for instance), my inclination is to leave this, as I said at the start, 
but I'd like a second opinion.

tl;dr: RFC lawyer material; probably Won't Fix; need a second opinion.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=64948


--
Edit this bug report at https://bugs.php.net/bug.php?id=64948&edit=1


Thread (17 messages)

« previous php.bugs (#217573) next »