Bug #77331 [Ver->Nab]: FILTER_VALIDATE_DOMAIN fail on example.org/wat
| From: | cmb@php.net | Date: | Tue, 06 Apr 2021 15:23:55 +0000 |
| Subject: | Bug #77331 [Ver->Nab]: FILTER_VALIDATE_DOMAIN fail on example.org/wat | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233229@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77331&edit=1
ID: 77331
Updated by: cmb@php.net
Reported by: divinity76 at gmail dot com
Summary: FILTER_VALIDATE_DOMAIN fail on example.org/wat
-Status: Verified
+Status: Not a bug
Type: Bug
Package: Unknown/Other Function
Operating System: Win7 x64 & Ubuntu 18.04
PHP Version: 7.2
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
FILTER_VALIDATE_DOMAIN without FILTER_FLAG_HOSTNAME works as
documented[1]; the fact that it's most useless, doesn't make it a
bug.
If you want the behavior to change, please pursue the RFC
process[2].
[1] <https://www.php.net/manual/en/filter.filters.validate.php>
[2] <https://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2019-01-24 19:21:05] divinity76 at gmail dot com
@ a at b dot c dot de
quote > Meanwhile, FILTER_FLAG_HOSTNAME rejects domains with legal hyphens:
- actually, when filter_var is user properly, it allows those domains (FILTER_FLAG_HOSTNAME goes as
the third argument, don't xor it into the 2nd argument)
var_dump(
// A hyphen with a well-known story behind it
filter_var('experts-exchange.com',
FILTER_VALIDATE_DOMAIN, FILTER_FLAG_HOSTNAME),
// Punycode (Greek test TLD)
filter_var('xn--jxalpdlp',
FILTER_VALIDATE_DOMAIN, FILTER_FLAG_HOSTNAME)
);
returns bool(true) bool(true)
------------------------------------------------------------------------
[2018-12-22 14:22:26] php at bitm dot sg
I want to add here that a whitespace and empty string should probably pass in the future. Empty
string refers to the DNS Root: https://en.wikipedia.org/wiki/Fully_qualified_domain_name#Syntax
------------------------------------------------------------------------
[2018-12-22 09:09:57] divinity76 at gmail dot com
@ a at b dot c dot de ,
this is not a comment on the validity of your claim, but you are using filter_var wrong,
FILTER_FLAG_HOSTNAME goes as the third parameter, it is not supposed to be bitwise-or'ed into
the 2nd parameter. (filter_var is weird, check the docs)
------------------------------------------------------------------------
[2018-12-22 03:36:49] a at b dot c dot de
FILTER_VALIDATE_DOMAIN is only looking at the lengths of the domain string and those of the bits
between '.' characters (this is documented but doesn't seem hugely useful).
var_dump(
filter_var('***.****',FILTER_VALIDATE_DOMAIN),
filter_var('!',FILTER_VALIDATE_DOMAIN),
filter_var('*******',FILTER_VALIDATE_DOMAIN),
filter_var(str_repeat('*', 63),FILTER_VALIDATE_DOMAIN),
filter_var(str_repeat('*', 64),FILTER_VALIDATE_DOMAIN) // Too long
);
Meanwhile, FILTER_FLAG_HOSTNAME rejects domains with legal hyphens:
var_dump(
// A hyphen with a well-known story behind it
filter_var('experts-exchange.com',
FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME),
// Punycode (Greek test TLD)
filter_var('xn--jxalpdlp',
FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME)
);
------------------------------------------------------------------------
[2018-12-20 23:29:21] cmb@php.net
See <https://3v4l.org/QRW3K>.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77331
--
Edit this bug report at https://bugs.php.net/bug.php?id=77331&edit=1