Bug #77364 [Opn->Nab]: preg_quote incorrectly escapes # character

From: Date: Wed, 02 Jan 2019 09:32:25 +0000
Subject: Bug #77364 [Opn->Nab]: preg_quote incorrectly escapes # character
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218732@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77364&edit=1 ID: 77364 Updated by: nikic@php.net Reported by: peku33 at gmail dot com Summary: preg_quote incorrectly escapes # character -Status: Open +Status: Not a bug Type: Bug Package: *Regular Expressions Operating System: Linux PHP Version: 7.3.0 Block user comment: N Private report: N New Comment: Yeah, this is an intentional change (and documented on http://php.net/preg_quote), and I don't believe we will go back on it. "#" is a special character inside regular expressions under some circumstances, and not escaping it could result in a security issue. In your particular case, it looks like you should be able to accommodate the new behavior by replacing both '\#' and '#' with '\d'. Previous Comments: ------------------------------------------------------------------------ [2018-12-28 23:05:52] cmb@php.net > preg_quote function escapes # character, while it shouldn't. This has been deliberately done to fix bug #75355. Unfortunately, this ticket has missed the deadline[1], and it seems to me that reverting now could do more harm than good. [1] <https://github.com/php/php-src/pull/2838#issuecomment-352194335> ------------------------------------------------------------------------ [2018-12-28 17:00:10] peku33 at gmail dot com Description: ------------ preg_quote function escapes # character, while it shouldn't. This breaks IPBoard 4.3.6 forums in which friendly urls uses custom regexes with #, @, ? characters in url templates. Urls are passed through preg_quote function and # is replaced with \#. In next section {#} should be replaced with (\d+), but this fails, since there is {#} but {\#}. PHP 7.3.0-2 (cli) (built: Dec 17 2018 09:51:53) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.3.0-dev, Copyright (c) 1998-2018 Zend Technologies with Zend OPcache v7.3.0-2, Copyright (c) 1999-2018, by Zend Technologies Test script: --------------- <?php $inputs = ['#', '?', '@']; foreach($inputs as $input) { var_dump($input, preg_quote($input)); } Expected result: ---------------- string(1) "#" string(1) "#" string(1) "?" string(2) "\?" string(1) "@" string(1) "@" Actual result: -------------- string(1) "#" string(2) "\#" string(1) "?" string(2) "\?" string(1) "@" string(1) "@" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77364&edit=1

« previous php.bugs (#218732) next »