Bug #78749 [Opn]: Wrong error message when maxOccurs is exceeded
| From: | tony at marston-home dot demon dot co dot uk | Date: | Thu, 28 Nov 2019 18:13:09 +0000 |
| Subject: | Bug #78749 [Opn]: Wrong error message when maxOccurs is exceeded | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223922@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78749&edit=1
ID: 78749
User updated by: tony at marston-home dot demon dot co dot uk
Reported by: tony at marston-home dot demon dot co dot uk
Summary: Wrong error message when maxOccurs is exceeded
Status: Open
Type: Bug
Package: SOAP related
Operating System: Windows 10
PHP Version: 7.3.11
Block user comment: N
Private report: N
New Comment:
Your statement that "The data does not *need* to be validated because the developer is supposed
to know what they're doing" is not accurate. All input validation, whether it be to
validate user input or developer input, is supposed to be carried out to ensure that the person
providing the input has not made a mistake.
In the case of WSDL validation this is supposed to check the following:
a) That the structure of the XML request matches the structure in the WSDL.
b) That elements with minOccurs=1 actually exist.
c) That elements do not occur more than maxOccurs times.
This means that elements in the XML structure which do not appear in the WSDL structure should cause
an error, and that any violation of either minOccurs or maxOccurs should cause an error. This means
that if I specify maxOccurs=2 in the WSDL but accidentally put 3 occurrences in the XML then this
should cause an error. It's not rocket science.
It is also possible to have a <contacts> element with minOccurs=0 to be a container for a
<contact> element with minOccurs=1. This signifies that the <contacts> element is
optional, but if it is supplied then it must contain at least 1 <contact> element.
Previous Comments:
------------------------------------------------------------------------
[2019-11-06 12:00:09] tony at marston-home dot demon dot co dot uk
All the while you try to squirm out of the fact that your code is not validating an XML document
against the WSDL definition, specifically the value for maxOccurrs on any element AS DOCUMENTED IN
THE W3C SPECIFICATION, then I will carry on complaining. Your idea that "Currently PHP only
really cares if maxOccurs>1 or not" is clearly wrong as the value "1" should be
validated as well.
------------------------------------------------------------------------
[2019-11-06 11:42:40] requinix@php.net
So much for avoiding "repeating ourselves until the other person gives up".
------------------------------------------------------------------------
[2019-11-06 10:30:39] tony at marston-home dot demon dot co dot uk
This is NOT a documentation error as your implementation clearly does NOT follow the WSDL
specification.
------------------------------------------------------------------------
[2019-11-06 10:23:09] tony at marston-home dot demon dot co dot uk
You may not be familiar with my use of a <contacts> element which is a container for 1 or more
<contact> elements, but if you look at the example XML document in http://www.w3.org/TR/xmlschema-0/#PO you will see
that it has an <items> element which is a container for one or more <item> elements.
The <items> element has an implied maxOccurs of 1, and in my test data my <contacts>
element has an explicit maxOccurs of 1. The <item> element has a maxOccurs of
"unbounded", and in my test data my <contact> element has a specified limit, and I
am testing to see what happens if the limit is exceeded when I supply 3 occurrences. If the
maxOccurs value is 1 the error message is wrong. If the maxOccurs value is 2 there is no error
message.
You said in your reply that "Currently PHP only really cares if maxOccurs>1 or not."
This is clearly wrong. The WSDL specification clearly states that the maxOccurs value defines
"The maximum number of times an element may appear" and as "1" is a valid value
the XML document should be validated to ensure that this limit is not violated. This is not an
optional piece of validation, it is REQUIRED.
------------------------------------------------------------------------
[2019-11-06 09:45:11] tony at marston-home dot demon dot co dot uk
It is clear that you do not understand the structure that I am using.
<contacts> is a container that can occur 0 or 1 times. It can contain a number of
<contact> elements (arrayOfContactInfo) which themselves are containers for other elements.
It is the value of maxOccurs for the <contact> element which is being problematic. Although my
data creates 3 occurrences I was testing to see what happens when I set maxOccurs to a smaller
value.
If I set it to 2 it does not complain that I have exceeded the maxOccurs value.
If I set it to 1 it does complain, but the error message is totally wrong.
The official specification at http://www.w3.org/TR/xmlschema-0/#OccurrenceConstraints
contains the sentence "The maximum number of times an element may appear is determined by the
value of a maxOccurs attribute in its declaration." Your code is clearly not validating the
maxOccurs value, therefore your code is not following the specification.
You say that the data does not *need* to be validated because the developer is supposed to know what
they're doing, but you are missing the whole point of WSDL/XSD/DTD validation which verifies
that the XML document which it is given conforms to the specified structure in order to trap any
mistakes made by the developer. It is supposed to guarantee that the XML document which is received
at the other end is exactly as expected. It does this by looking at the minOccurs and maxOccurs
value for each element. An element is optional if minOccurs is zero but required if it is greater
than zero. The specification also states that no element should occur more times than as stated in
the maxOccurs value. Your code is NOT doing this, therefore your code does NOT conform to the
specification.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78749
--
Edit this bug report at https://bugs.php.net/bug.php?id=78749&edit=1