Req #65252 [Opn->Sus]: Input string parsing - allow ' ' and '.' chars as hash key
| From: | cmb@php.net | Date: | Mon, 08 Feb 2021 14:25:47 +0000 |
| Subject: | Req #65252 [Opn->Sus]: Input string parsing - allow ' ' and '.' chars as hash key | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232013@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65252&edit=1
ID: 65252
Updated by: cmb@php.net
Reported by: matti dot jarvinen at nitroid dot fi
Summary: Input string parsing - allow ' ' and '.' chars as
hash key
-Status: Open
+Status: Suspended
Type: Feature/Change Request
Package: URL related
Operating System: *
PHP Version: master
Block user comment: N
Private report: N
New Comment:
This topic comes up in internals discussions from time to time.
Unless someone pursues the RFC process[1], nothing will change. :(
[1] <https://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2013-11-23 15:07:44] dan dot lugg at gmail dot com
I'd like to second this report/request. With register_globals having been deprecated and
removed quite some time ago now, it would be great to see some of the accommodations made for that
feature cleaned up.
While it is perfectly understandable that this could cause BC breaks, an INI flag would certainly
fix this.
; Can be set to "" to prevent
; replacement altogether
form_char_replace=". "
------------------------------------------------------------------------
[2013-07-19 22:59:31] yohgaki@php.net
This may break apps, but request is debatable.
------------------------------------------------------------------------
[2013-07-12 13:33:24] matti dot jarvinen at nitroid dot fi
Description:
------------
Since register_globals has been removed in PHP 5.4.0 there should be no reason other than legacy why
input variables ($_POST, $_GET, $_FILES, $_COOKIE, $_REQUEST) can not have keys containing following
characters
chr(32) ( ) (space)
chr(46) (.) (dot)
Documentation states that only . is changed to _ but same goes for above characters.
http://www.php.net/manual/en/language.variables.external.php
Test script:
---------------
<form method="POST">
<input type="text" name="foo bar" value="spaced" />
<input type="text" name="foo.bar" value="dotted" />
<input type="submit" value="send" />
</form>
<?php
if(isset($_POST))
{
print_r($_POST);
}
?>
Expected:
array(
"foo bar"=>'spaced',
"foo.bar"=>'dotted'
);
Actual result:
array(
"foo_bar"=>'dotted'
);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65252&edit=1