Bug #77089 [Com]: An email with an invalid character passes filter_var validation

From: Date: Wed, 31 Oct 2018 15:55:57 +0000
Subject: Bug #77089 [Com]: An email with an invalid character passes filter_var validation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217773@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77089&edit=1 ID: 77089 Comment by: nospam at relianthost dot co dot uk Reported by: marco dot bagnaresi at golee dot it Summary: An email with an invalid character passes filter_var validation Status: Open Type: Bug Package: *Mail Related Operating System: Windows PHP Version: 7.1.23 Block user comment: N Private report: N New Comment: See: https://secure.php.net/manual/en/filter.filters.sanitize.php > FILTER_SANITIZE_EMAIL > Remove all characters except letters, digits and !#$%&'*+-=?^_`{|}~@.[]. This is not a bug, as the filter does as the documentation intended. Previous Comments: ------------------------------------------------------------------------ [2018-10-31 15:26:50] marco dot bagnaresi at golee dot it Description: ------------ An email with an invalid character ' is filtered as a valid email. Test script: --------------- $email = "hello'@world.it"; $sanitized_email = filter_var($email, FILTER_SANITIZE_EMAIL); $this->assertEquals($email,$sanitized_email,"The email should not be valid!"); Expected result: ---------------- The email should not pass validation. Actual result: -------------- The email is returned from the filter_var function. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77089&edit=1

« previous php.bugs (#217773) next »