Bug #71822 [Opn->Csd]: parse_url on 7.1.0-dev returns false where password contains a `-` character
| From: | stas@php.net | Date: | Tue, 18 Dec 2018 08:13:07 +0000 |
| Subject: | Bug #71822 [Opn->Csd]: parse_url on 7.1.0-dev returns false where password contains a `-` character | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218508@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71822&edit=1
ID: 71822
Updated by: stas@php.net
Reported by: nigel dot greenway at futurepixels dot co dot uk
Summary: parse_url on 7.1.0-dev returns false where password
contains a
- character
-Status: Open
+Status: Closed
Type: Bug
Package: *URL Functions
Operating System: Linux - BunsenLabs
PHP Version: Next Major Version
-Assigned To:
+Assigned To: stas
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2016-10-12 14:35:23] cilefen at gmail dot com
It looks like the commit that caused this was reverted: https://github.com/php/php-src/commit/1c468ee044289661c8c4118a0653222596668432
------------------------------------------------------------------------
[2016-10-07 20:39:54] cilefen at gmail dot com
Underscores "_" also cause a return of false.
------------------------------------------------------------------------
[2016-10-07 20:16:18] cilefen at gmail dot com
This is causing test failures in Drupal 8 HEAD, https://www.drupal.org/node/2813981.
------------------------------------------------------------------------
[2016-09-07 14:51:13] andi at splitbrain dot org
The same problem occurs with a space in the password. I am aware that this might not be a valid URL
as is (space should be escaped) however this used to work on PHP 7.0
<?php
$x = parse_url('http://foo:foo bar@example.com/');
var_dump($x);
?>
------------------------------------------------------------------------
[2016-03-15 07:09:24] yohgaki@php.net
https://3v4l.org/UusRf
It seems released versions are fine.
unreserved = ALPHA / DIGIT / "-" / "." / "_" / "~"
pct-encoded = "%" HEXDIG HEXDIG
sub-delims = "!" / "$" / "&" / "'" /
"(" / ")"
/ "*" / "+" / "," / ";" / "="
userinfo = *( unreserved / pct-encoded / sub-delims / ":" )
https://www.ietf.org/rfc/rfc3986.txt
"so-me:pass-word" should be valid username and password.
According to the RFC, "Use of the format "user:password" in the userinfo field is
deprecated.", but we need to support this format anyway.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71822
--
Edit this bug report at https://bugs.php.net/bug.php?id=71822&edit=1