Bug #79684 [Nab]: C14N sorts the attributes (incorrectly) when not loaded

From: Date: Wed, 10 Jun 2020 11:33:42 +0000
Subject: Bug #79684 [Nab]: C14N sorts the attributes (incorrectly) when not loaded
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227405@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79684&edit=1

 ID:                 79684
 User updated by:    and_spam+php_net at rump dot dk
 Reported by:        and_spam+php_net at rump dot dk
 Summary:            C14N sorts the attributes (incorrectly) when not
                     loaded
 Status:             Not a bug
 Type:               Bug
 Package:            DOM XML related
 Operating System:   Linux
 PHP Version:        7.3.18
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

cmb@php.net: I stand corrected. Thanks. Sorry for not looking at your code example - I was to fast
and just thought you were linking to some standard text.


Previous Comments:
------------------------------------------------------------------------
[2020-06-10 07:48:34] and_spam+php_net at rump dot dk

You are totally correct [a at b dot c dot de] but also wrong. ;-)
C14N are used to extract the XML as a string just as saveXML but the content, incl. attributes, have
to be in a specific order so the hash of the text always return the same result.

------------------------------------------------------------------------
[2020-06-10 03:05:49] a at b dot c dot de

I for one am not seeing the difference between

<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
Version="2.0" id="IDCard"></saml:Assertion>

and 

<saml:Assertion Version="2.0" id="IDCard"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"></saml:Assertion>

I mean, the attributes are in a different order, but that has no significance, right?[1]

[1] https://www.w3.org/TR/REC-xml/#sec-starttags

------------------------------------------------------------------------
[2020-06-09 21:44:12] cmb@php.net

The DOM living standard states[1]:

| Return a new attribute whose local name is localName […]

and[2]:

| Attributes have a […] namespace prefix (null or a non-empty
| string), local name (a non-empty string) […]

So

    $xml->createAttribute('xmlns:saml');

creates an attribute with *local name* 'xmlns:saml', which is not
magically converted to a namespace declaration on the attribute's
element.  You can see that when you var_dump() the respective
attribute[3]; it's just a regular attribute with the localName
'xmlns:saml', and the namespace URI as testContent.  When you
convert this element to its textual representation, it looks like
its properly namespaced pendant, but it isn't quite the same
(unless reparsed).

[1] <https://dom.spec.whatwg.org/#dom-document-createattribute>
[2] <https://dom.spec.whatwg.org/#concept-attribute-local-name>
[3] <https://3v4l.org/NNUsV>

------------------------------------------------------------------------
[2020-06-09 18:01:01] and_spam+php_net at rump dot dk

It is a bug!

The XML was just the smallest sample I could create to prove the point.
I could create a full code as suggested but the result is exactly the same.

Please reopen and examine this ticket. I can provide way more code if you want to.

------------------------------------------------------------------------
[2020-06-09 16:29:11] cmb@php.net

Just adding the namespace declaration as normal attribute is not
supported.  You should instead create the saml:Assertion element
as node with associated namespace; see <https://3v4l.org/lsIVL>
for the correct code.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=79684


--
Edit this bug report at https://bugs.php.net/bug.php?id=79684&edit=1


Thread (7 messages)

« previous php.bugs (#227405) next »