Bug #79684 [Nab]: C14N sorts the attributes (incorrectly) when not loaded

From: Date: Wed, 10 Jun 2020 07:48:34 +0000
Subject: Bug #79684 [Nab]: C14N sorts the attributes (incorrectly) when not loaded
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227391@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79684&edit=1

 ID:                 79684
 User updated by:    and_spam+php_net at rump dot dk
 Reported by:        and_spam+php_net at rump dot dk
 Summary:            C14N sorts the attributes (incorrectly) when not
                     loaded
 Status:             Not a bug
 Type:               Bug
 Package:            DOM XML related
 Operating System:   Linux
 PHP Version:        7.3.18
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

You are totally correct [a at b dot c dot de] but also wrong. ;-)
C14N are used to extract the XML as a string just as saveXML but the content, incl. attributes, have
to be in a specific order so the hash of the text always return the same result.


Previous Comments:
------------------------------------------------------------------------
[2020-06-10 03:05:49] a at b dot c dot de

I for one am not seeing the difference between

<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
Version="2.0" id="IDCard"></saml:Assertion>

and 

<saml:Assertion Version="2.0" id="IDCard"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"></saml:Assertion>

I mean, the attributes are in a different order, but that has no significance, right?[1]

[1] https://www.w3.org/TR/REC-xml/#sec-starttags

------------------------------------------------------------------------
[2020-06-09 21:44:12] cmb@php.net

The DOM living standard states[1]:

| Return a new attribute whose local name is localName […]

and[2]:

| Attributes have a […] namespace prefix (null or a non-empty
| string), local name (a non-empty string) […]

So

    $xml->createAttribute('xmlns:saml');

creates an attribute with *local name* 'xmlns:saml', which is not
magically converted to a namespace declaration on the attribute's
element.  You can see that when you var_dump() the respective
attribute[3]; it's just a regular attribute with the localName
'xmlns:saml', and the namespace URI as testContent.  When you
convert this element to its textual representation, it looks like
its properly namespaced pendant, but it isn't quite the same
(unless reparsed).

[1] <https://dom.spec.whatwg.org/#dom-document-createattribute>
[2] <https://dom.spec.whatwg.org/#concept-attribute-local-name>
[3] <https://3v4l.org/NNUsV>

------------------------------------------------------------------------
[2020-06-09 18:01:01] and_spam+php_net at rump dot dk

It is a bug!

The XML was just the smallest sample I could create to prove the point.
I could create a full code as suggested but the result is exactly the same.

Please reopen and examine this ticket. I can provide way more code if you want to.

------------------------------------------------------------------------
[2020-06-09 16:29:11] cmb@php.net

Just adding the namespace declaration as normal attribute is not
supported.  You should instead create the saml:Assertion element
as node with associated namespace; see <https://3v4l.org/lsIVL>
for the correct code.

------------------------------------------------------------------------
[2020-06-09 15:25:40] and_spam+php_net at rump dot dk

Description:
------------
The test script perform the same operation twice but the result (the last two lines) are different
depending on if the XML has been created dynamically or loaded (in this case by storing the
dynamically created XML and (re)loading it).

You may reorder the createAttribute lines as you want but the last two lines will always be the same
- the last line being correct.

Test script:
---------------
$xml = new DOMDocument();

$element = $xml->createElement('saml:Assertion');
$xml_saml_assertion = $xml->appendChild($element);
	
$attribute = $xml->createAttribute('id');
$attribute->value = 'IDCard';
$xml_saml_assertion->appendChild($attribute);
	
$attribute = $xml->createAttribute('xmlns:saml');
$attribute->value = 'urn:oasis:names:tc:SAML:2.0:assertion';
$xml_saml_assertion->appendChild($attribute);
	
$attribute = $xml->createAttribute('Version');
$attribute->value = '2.0';
$xml_saml_assertion->appendChild($attribute);

print("<pre>" . htmlentities($xml->saveXML()) .
"</pre><br>\n");
print("<pre>" . htmlentities($xml->C14N(TRUE)) .
"</pre><br>\n");
$xml->loadXML($xml->saveXML());
print("<pre>" . htmlentities($xml->C14N(TRUE)) .
"</pre><br>\n");

Expected result:
----------------
<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
Version="2.0" id="IDCard"></saml:Assertion>



Actual result:
--------------
<saml:Assertion Version="2.0" id="IDCard"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"></saml:Assertion>


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79684&edit=1


Thread (7 messages)

« previous php.bugs (#227391) next »