#13961 [Fbk->NoF]: some characters in incomonig variable names are silently changed

From: Date: Tue, 15 Oct 2002 06:00:03 +0000
Subject: #13961 [Fbk->NoF]: some characters in incomonig variable names are silently changed
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-22472@lists.php.net to get a copy of this message
ID: 13961 Updated by: php-bugs@lists.php.net Reported By: lampa@fee.vutbr.cz -Status: Feedback +Status: No Feedback Bug Type: Apache related Operating System: FreeBSD PHP Version: 4.0.6, 4.1.0 Assigned To: derick New Comment: No feedback was provided for this bug for over 2 weeks, so it is being suspended automatically. If you are able to provide the information that was originally requested, please do so and change the status of the bug back to "Open". Previous Comments: ------------------------------------------------------------------------ [2002-09-29 20:41:13] sniper@php.net Please try using this CVS snapshot: http://snaps.php.net/php4-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-latest.zip This should be fixed in CVS (If I remember correctly) so could you please try the snapshot and verify it for us? ------------------------------------------------------------------------ [2001-12-11 09:57:36] lampa@fee.vutbr.cz Not fixed in 4.1.0. Why? To be clear, one call is neccessary: for (i = 0; i < arr->nelts; i++) { char *val,*key; if (elts[i].val) { val = elts[i].val; } else { val = empty_string; } key = estrdup(elts[i].key); /* HERE */ php_register_variable(key, val, track_vars_array ELS_CC PLS_CC) ; } ------------------------------------------------------------------------ [2001-11-07 04:33:03] derick@php.net This is not okay, PHP should not change the original key here. Checking it out. ------------------------------------------------------------------------ [2001-11-07 01:56:30] lampa@fee.vutbr.cz I don't think that FAQ solves that problem. Look at the source code of Apache server. There are several tests of the variable "force-response-1.0" there. The problem is not that php code variable is $force-response-1_0, that's OK, but the real problem is that apache variable name in r->subprocess_env is changed too. That's side effect and not pleasent. ------------------------------------------------------------------------ [2001-11-06 16:30:56] jeroen@php.net This is mentioned in http://uk.php.net/manual/en/faq.html.php#AEN63677 . Impossible to find if you don't know where to find it. So changing this to a documentation problem. (the issue is that invalid characters in incoming variable names, like dots, are converted to underscores. This happens with any incoming variable name, be it GET, POST, ENV, or whatever.) Changed subject ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/13961 -- Edit this bug report at http://bugs.php.net/?id=13961&edit=1

« previous php.bugs (#22472) next »