Edit report at https://bugs.php.net/bug.php?id=76469&edit=1
ID: 76469
Updated by: heiglandreas@php.net
Reported by: clement dot oudot at worteks dot com
Summary: ldap_bind should return NULL when called with wrong
types
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: LDAP related
Operating System: GNU/Linux
PHP Version: 7.1.18
-Assigned To:
+Assigned To: heiglandreas
Block user comment: N
Private report: N
New Comment:
ldap_bind binds (aka authenticates) a user against the LDAP-server. The method returns - as clearly
stated in the docs - true if the bind is succesfull and false in any other cases. As the method
expects string-parameters it simply returns false without setting ldap_errno when no strings are
given as parameters. It is the responsibility of the user to check for the right types of values. As
it is the responsibility of the user to make sure that ldap_bind is not called with a username but
no password at all.
Therefore I'm closing this as it is against the purpose of an authentication function to return
something else than "authenticated" and "not authenticated".
Previous Comments:
------------------------------------------------------------------------
[2018-06-13 20:35:08] cmb@php.net
Even though I don't think it is be helpful for anybody, I'm
re-opening this ticket as feature request.
------------------------------------------------------------------------
[2018-06-13 17:12:01] clement dot oudot at worteks dot com
I agree we can check parameters before calling ldap_bind. But what if we have another error when
calling built-in function?
It would be great that ldap_bind returns NULL if there is an error when calling ldap_bind, and 0 if
ldap_bind does the LDAP operation and the return is and LDAP error. For the moment, it retuns also
NULL. It returns 1 if the LDAP operation returns success.
------------------------------------------------------------------------
[2018-06-13 16:35:11] cmb@php.net
> Now I see that ldap_bind return FALSE if the call to function was> bad (Array instead of string for example), [â¦]
Indeed! (uncommon, but conforming to the docs)
> There is no way to do the difference in the code, or did I miss> something?
Besides that you could catch or resolve the case of a wrong
parameter type before even calling ldap_bind(), you could still
call ldap_errno() afterwards, which will return FALSE in the first
case, and an integer in the latter.
------------------------------------------------------------------------
[2018-06-13 15:55:16] clement dot oudot at worteks dot com
Thanks, We will indeed check the object that is passed as parameter.
Now I see that ldap_bind return FALSE if the call to function was bad (Array instead of string for
example), which does not play the operation on LDAP directory, but also when the operation is done
on LDAP directory and the return is not success.
There is no way to do the difference in the code, or did I miss something?
------------------------------------------------------------------------
[2018-06-13 15:46:28] cmb@php.net
The documentation states[1]:
| If the parameters given to a function are not what it expects,
| such as passing an array where a string is expected, the return
| value of the function is undefined. In this case it will likely
| return NULL but this is just a convention, and cannot be relied
| upon.
I'm pretty sure that PHP will never return TRUE, so you can check
the return value of ldap_bind(). However, it's better to ensure
that you pass a string (or something compatible in weak type mode)
in the first place.
[1] <http://php.net/manual/en/functions.internal.php>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76469
--
Edit this bug report at https://bugs.php.net/bug.php?id=76469&edit=1