Bug #79178 [Opn->Nab]: [parse_url] underscore at end of host
| From: | patrickallaert@php.net | Date: | Wed, 09 Jun 2021 15:27:20 +0000 |
| Subject: | Bug #79178 [Opn->Nab]: [parse_url] underscore at end of host | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234310@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79178&edit=1
ID: 79178
Updated by: patrickallaert@php.net
Reported by: progr-d at yandex dot ru
Summary: [parse_url] underscore at end of host
-Status: Open
+Status: Not a bug
Type: Bug
Package: *URL Functions
Operating System: macOS 10.13.6
PHP Version: 7.3.14
Block user comment: N
Private report: N
New Comment:
The "_" has been used to prevent CR/LF injection issues, see: https://github.com/php/php-src/commit/184323cbe5ca9407acc41f421800df360757c6f6
I don't really know what you should expect from parse_url() provided that you give him an
invalid URL.
Expecting "yandex.ru" while the host "yandex.ru\n" has been provided feels wrong
to me.
What would you expect from:
var_dump(parse_url("http://yan\ndex.ru\n",
PHP_URL_HOST));
for example?
To me, your case and the one above could equally give: bool(false) IMHO.
I am closing this issue (and the related PR) as it isn't really a bug, nor it has evolved in 17
months and there is no clear outcome of what to expect from parsing invalid URLs.
You are very welcome to re-open this issue and/or it's PR if you have more thoughts about it.
Previous Comments:
------------------------------------------------------------------------
[2020-03-01 00:31:07] nawarian at gmail dot com
While parsing many parts of the url (scheme, user, pass, host, fragment, query, path) php behaves
this way: whenever it finds parts of the string being a control character (cctype::iscntrl) it
replaces such character with an underscore.
Why? I don't know...
I've submitted a pull request fixing the behaviour mentioned on "host" part only. But
such issue will keep happening on every url part I've mentioned before.
I wouldn't mind fixing those as well, but sounds like a bigger change that affects the API.
Thoughts?
------------------------------------------------------------------------
[2020-03-01 00:24:38] nawarian at gmail dot com
The following pull request has been associated:
Patch Name: Fix #79178 parse_url check control chars on host
On GitHub: https://github.com/php/php-src/pull/5225
Patch: https://github.com/php/php-src/pull/5225.patch
------------------------------------------------------------------------
[2020-01-27 19:22:02] progr-d at yandex dot ru
Description:
------------
When processing a file through function
file, I met this feature, which I could not
have expected in this place.
Yes, I know that you need to use flag FILE_IGNORE_NEW_LINES, but having received an underscore, for
a long time I could not understand where it came from.
Test script:
---------------
var_dump(parse_url('http://yandex.ru' . PHP_EOL,
PHP_URL_HOST));
Expected result:
----------------
string(10) "yandex.ru"
or
Exception
Actual result:
--------------
string(10) "yandex.ru_"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79178&edit=1