Bug #77089 [Com]: An email with an invalid character passes filter_var validation
| From: | nospam at relianthost dot co dot uk | Date: | Wed, 31 Oct 2018 15:55:57 +0000 |
| Subject: | Bug #77089 [Com]: An email with an invalid character passes filter_var validation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217773@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77089&edit=1
ID: 77089
Comment by: nospam at relianthost dot co dot uk
Reported by: marco dot bagnaresi at golee dot it
Summary: An email with an invalid character passes filter_var
validation
Status: Open
Type: Bug
Package: *Mail Related
Operating System: Windows
PHP Version: 7.1.23
Block user comment: N
Private report: N
New Comment:
See: https://secure.php.net/manual/en/filter.filters.sanitize.php
> FILTER_SANITIZE_EMAIL
> Remove all characters except letters, digits and !#$%&'*+-=?^_`{|}~@.[].
This is not a bug, as the filter does as the documentation intended.
Previous Comments:
------------------------------------------------------------------------
[2018-10-31 15:26:50] marco dot bagnaresi at golee dot it
Description:
------------
An email with an invalid character ' is filtered as a valid email.
Test script:
---------------
$email = "hello'@world.it";
$sanitized_email = filter_var($email, FILTER_SANITIZE_EMAIL);
$this->assertEquals($email,$sanitized_email,"The email should not be valid!");
Expected result:
----------------
The email should not pass validation.
Actual result:
--------------
The email is returned from the filter_var function.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77089&edit=1