Bug #67887 [Com]: the URL rewrite mechanism handles `<a href=\"javascript` in a surprising manner

From: Date: Mon, 19 Jul 2021 09:29:06 +0000
Subject: Bug #67887 [Com]: the URL rewrite mechanism handles `<a href=\"javascript` in a surprising manner
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235162@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67887&edit=1

 ID:                 67887
 Comment by:         shubhrapandit1612 at gmail dot com
 Reported by:        ndermine at adequasys dot com
 Summary:            the URL rewrite mechanism handles `<a
                     href=\"javascript` in a surprising manner
 Status:             Open
 Type:               Bug
 Package:            Output Control
 Operating System:   windows, mac os x, debian
 PHP Version:        5.5.16
 Block user comment: N
 Private report:     N

 New Comment:

Thank you for sharing. I found this code helpful.
https://www.sevenmentor.com/java-classes-in-bangalore


Previous Comments:
------------------------------------------------------------------------
[2020-07-01 17:46:51] php at yopmail dot com

Always the problème in 2020 !!!

If js code in HTML like that :

some text
<script>
var m = $("<a href=\"\/my\/url\">label</a>") ;
</script>

it is transformed in :

some text
<script>
var m = $("<a href=\?a=b"\/my\/url\">label</a>") ;
</script>

------------------------------------------------------------------------
[2014-11-04 14:19:36] datatablesstr-1 at yahoo dot gr

I face a similar problem since I upgraded from PHP 5.4.16 to PHP 5.4.29 (also Zend Server 6.0.1 to
Zend Server 7.0.0), on various Windows OS (Win7 and Server 2003, 2008) and also to both IIS and
Apache (various versions).

Unfortunately I can not supply any code as the application is copyrighted but I will provide you
some information and the output results.

The concept is that the phpinfo() is called, parsed, minified and returned inside a JSON object. A
part of the code is the following:

ob_start();
phpinfo();
$phpinfo = trim(str_replace(array("\r","\n","\t"), "",
ob_get_contents()));
ob_end_clean();
$component->contents = $phpinfo;

Then the component is passing through a lot of functions etc leading to the output...

Starting from the "normal" or expected output, which is also the "correct"
output, returned since many years and several PHP versions (now with the 5.4.16 for example):

... <td><a href=\"http:\/\/www.php.net\/\"><img
border=\"0\" ...


Instead from the above, I get with PHP5.4.29 the following (exactly with the blank spaces etc):

... <td><a href=\?ApplId=f29bp4f03fmo1juomiaup7m851" http :  \  /  \  / www.php.net \ 
/  \ "><img border=\"0\" ...

-------------------------------------------------------------------------
I found out that the responsible configuration can be found in php.ini, which is the same in both
old and new setups (PHP5.4.16 vs PHP5.4.29)

url_rewriter.tags="a=href,area=href,frame=src,input=src,form=fakeentry"


when I replace/deactivate the url_rewriter with the following:

url_rewriter.tags=""

I get the correct result, as it used to be output in PHP 5.4.16.


I hope my comment provides some helpful extra information.


Best Regards,
Steven

------------------------------------------------------------------------
[2014-08-22 14:32:48] ndermine at adequasys dot com

Description:
------------
I use output_add_rewrite_var to add a URL parameter to relative links in my app.

When I have a link like this <a href="javascript:..."> it is left untouched which is
great.

But I had a piece of javascript containing an anchor tag inside a javascript string :
"<a href=\"javascript..." (note the escaped double quote that is expected to
remain escaped in the HTML page source)

That part was modified in a way that broke the javascript : the new param was introduced between the
backslash and the double quote :

"<a href=\?key=value"javascript..."

I can of course write (and have rewritten) my javascript differently, but would it be possible to
not insert the parameters in this case?

This seems very similar to Bug #19358 "URL Rewriter Blindly Replaces All Links" (closed
because of lack of feedback) which was submitted in 2002.

Thank you for your work.

Test script:
---------------
<?php
output_add_rewrite_var('a', 'b');
?>
<script type="text/javascript">
var link = "<a href=\"javascript:doSomething('with a
parameter')\">link</a>";
</script>


Expected result:
----------------
<script type="text/javascript">
var link = "<a href=\"javascript:doSomething('with a
parameter')\">link</a>";
</script>

Actual result:
--------------
<script type="text/javascript">
var link = "<a href=\?a=b"javascript:doSomething('with a
parameter')\">link</a>";
</script>


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67887&edit=1


Thread (4 messages)

« previous php.bugs (#235162) next »