Bug #77331 [Ver->Nab]: FILTER_VALIDATE_DOMAIN fail on example.org/wat

From: Date: Tue, 06 Apr 2021 15:23:55 +0000
Subject: Bug #77331 [Ver->Nab]: FILTER_VALIDATE_DOMAIN fail on example.org/wat
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233229@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77331&edit=1 ID: 77331 Updated by: cmb@php.net Reported by: divinity76 at gmail dot com Summary: FILTER_VALIDATE_DOMAIN fail on example.org/wat -Status: Verified +Status: Not a bug Type: Bug Package: Unknown/Other Function Operating System: Win7 x64 & Ubuntu 18.04 PHP Version: 7.2 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: FILTER_VALIDATE_DOMAIN without FILTER_FLAG_HOSTNAME works as documented[1]; the fact that it's most useless, doesn't make it a bug. If you want the behavior to change, please pursue the RFC process[2]. [1] <https://www.php.net/manual/en/filter.filters.validate.php> [2] <https://wiki.php.net/rfc/howto> Previous Comments: ------------------------------------------------------------------------ [2019-01-24 19:21:05] divinity76 at gmail dot com @ a at b dot c dot de quote > Meanwhile, FILTER_FLAG_HOSTNAME rejects domains with legal hyphens: - actually, when filter_var is user properly, it allows those domains (FILTER_FLAG_HOSTNAME goes as the third argument, don't xor it into the 2nd argument) var_dump( // A hyphen with a well-known story behind it filter_var('experts-exchange.com', FILTER_VALIDATE_DOMAIN, FILTER_FLAG_HOSTNAME), // Punycode (Greek test TLD) filter_var('xn--jxalpdlp', FILTER_VALIDATE_DOMAIN, FILTER_FLAG_HOSTNAME) ); returns bool(true) bool(true) ------------------------------------------------------------------------ [2018-12-22 14:22:26] php at bitm dot sg I want to add here that a whitespace and empty string should probably pass in the future. Empty string refers to the DNS Root: https://en.wikipedia.org/wiki/Fully_qualified_domain_name#Syntax ------------------------------------------------------------------------ [2018-12-22 09:09:57] divinity76 at gmail dot com @ a at b dot c dot de , this is not a comment on the validity of your claim, but you are using filter_var wrong, FILTER_FLAG_HOSTNAME goes as the third parameter, it is not supposed to be bitwise-or'ed into the 2nd parameter. (filter_var is weird, check the docs) ------------------------------------------------------------------------ [2018-12-22 03:36:49] a at b dot c dot de FILTER_VALIDATE_DOMAIN is only looking at the lengths of the domain string and those of the bits between '.' characters (this is documented but doesn't seem hugely useful). var_dump( filter_var('***.****',FILTER_VALIDATE_DOMAIN), filter_var('!',FILTER_VALIDATE_DOMAIN), filter_var('*******',FILTER_VALIDATE_DOMAIN), filter_var(str_repeat('*', 63),FILTER_VALIDATE_DOMAIN), filter_var(str_repeat('*', 64),FILTER_VALIDATE_DOMAIN) // Too long ); Meanwhile, FILTER_FLAG_HOSTNAME rejects domains with legal hyphens: var_dump( // A hyphen with a well-known story behind it filter_var('experts-exchange.com', FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME), // Punycode (Greek test TLD) filter_var('xn--jxalpdlp', FILTER_VALIDATE_DOMAIN | FILTER_FLAG_HOSTNAME) ); ------------------------------------------------------------------------ [2018-12-20 23:29:21] cmb@php.net See <https://3v4l.org/QRW3K>. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77331 -- Edit this bug report at https://bugs.php.net/bug.php?id=77331&edit=1

« previous php.bugs (#233229) next »