Bug #77331 [Com]: FILTER_VALIDATE_DOMAIN fail on example.org/wat

From: Date: Sat, 22 Dec 2018 14:22:26 +0000
Subject: Bug #77331 [Com]: FILTER_VALIDATE_DOMAIN fail on example.org/wat
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218568@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77331&edit=1 ID: 77331 Comment by: php at bitm dot sg Reported by: divinity76 at gmail dot com Summary: FILTER_VALIDATE_DOMAIN fail on example.org/wat Status: Verified Type: Bug Package: Unknown/Other Function Operating System: Win7 x64 & Ubuntu 18.04 PHP Version: 7.2 Block user comment: N Private report: N New Comment: I want to add here that a whitespace and empty string should probably pass in the future. Empty string refers to the DNS Root: https://en.wikipedia.org/wiki/Fully_qualified_domain_name#Syntax Previous Comments: ------------------------------------------------------------------------ [2018-12-22 09:09:57] divinity76 at gmail dot com @ a at b dot c dot de , this is not a comment on the validity of your claim, but you are using filter_var wrong, FILTER_FLAG_HOSTNAME goes as the third parameter, it is not supposed to be bitwise-or'ed into the 2nd parameter. (filter_var is weird, check the docs) ------------------------------------------------------------------------ [2018-12-22 03:36:49] a at b dot c dot de FILTER_VALIDATE_DOMAIN is only looking at the lengths of the domain string and those of the bits between '.' characters (this is documented but doesn't seem hugely useful). var_dump( filter_var('***.****',FILTER_VALIDATE_DOMAIN), filter_var('!',FILTER_VALIDATE_DOMAIN), filter_var('*******',FILTER_VALIDATE_DOMAIN), filter_var(str_repeat('*', 63),FILTER_VALIDATE_DOMAIN), filter_var(str_repeat('*', 64),FILTER_VALIDATE_DOMAIN) // Too long ); Meanwhile, FILTER_FLAG_HOSTNAME rejects domains with legal hyphens: var_dump( // A hyphen with a well-known story behind it filter_var('experts-exchange.com', FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME), // Punycode (Greek test TLD) filter_var('xn--jxalpdlp', FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME) ); ------------------------------------------------------------------------ [2018-12-20 23:29:21] cmb@php.net See <https://3v4l.org/QRW3K>. ------------------------------------------------------------------------ [2018-12-20 22:22:17] divinity76 at gmail dot com Description: ------------ FILTER_VALIDATE_DOMAIN fail to realize that "example.org/wat" is not a domain (URL? guess you can say that. domain? don't think so.) - interestingly, FILTER_VALIDATE_DOMAIN works fine if FILTER_FLAG_HOSTNAME is provided, the bug is only present when FILTER_FLAG_HOSTNAME is not provided. Test script: --------------- <?php var_dump( filter_var('example.org/wat',FILTER_VALIDATE_DOMAIN), filter_var('example.org/wat',FILTER_VALIDATE_DOMAIN,FILTER_FLAG_HOSTNAME) ); Expected result: ---------------- bool(false) bool(false) Actual result: -------------- string(15) "example.org/wat" bool(false) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77331&edit=1

« previous php.bugs (#218568) next »