Bug #81332 [Nab]: urn: URIs are not validated properly

From: Date: Thu, 05 Aug 2021 07:54:34 +0000
Subject: Bug #81332 [Nab]: urn: URIs are not validated properly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235606@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81332&edit=1

 ID:                 81332
 Updated by:         requinix@php.net
 Reported by:        tamas dot nagy0404 at outlook dot com
 Summary:            urn: URIs are not validated properly
 Status:             Not a bug
 Type:               Bug
 Package:            URL related
 Operating System:   all
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

> I think it is still a bug (or misdocumentation), you are referring to the
> http://www.faqs.org/rfcs/rfc2396.html in
> your manual for this function
> regardless what it is called which is about URIs, so it should either specify
> that only URLs are being validated or URIs too.

RFC 2396 defines the hierarchical format of a URL, which is why it's mentioned. Read section
1.2 to understand the difference between a URL and a URN.

> Also... for example news:comp.infosystems.www.servers.unix` is
> not a URL either
> however it passes the validation regardless.

Take another look:

Section 1.2
> The term "Uniform Resource Locator" (URL) refers to the subset of URI that
> identify resources via a representation of their primary access mechanism (e.g.,
> their network "location"), rather than identifying the resource by name or by
> some other attribute(s) of that resource.

https://en.wikipedia.org/wiki/URL
> A Uniform Resource Locator (URL), colloquially termed a web address, is a
> reference to a web resource that specifies its location on a computer network
> and a mechanism for retrieving it. A URL is a specific type of Uniform Resource
> Identifier (URI), although many people use the two terms interchangeably. URLs
> occur most commonly to reference web pages (http), but are also used for file
> transfer (ftp), email (mailto), database access (JDBC), and many other
> applications.

So actually yes, it *is* a URL. It may not be the type of URL that most people are familiar with,
like those starting with "http(s)" or containing a "www" or ".com",
but it still is one.


Previous Comments:
------------------------------------------------------------------------
[2021-08-05 07:23:15] tamas dot nagy0404 at outlook dot com

I think it is still a bug (or misdocumentation), you are referring to the http://www.faqs.org/rfcs/rfc2396.html in your
manual for this function regardless what it is called which is about URIs, so it should either
specify that only URLs are being validated or URIs too.

Also... for example news:comp.infosystems.www.servers.unix` is
not a URL either however it passes the validation regardless.

------------------------------------------------------------------------
[2021-08-05 07:09:58] requinix@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php

https://www.php.net/manual/en/filter.filters.validate.php
> Validates value as URL (according to » http://www.faqs.org/rfcs/rfc2396),
> optionally with required components. Beware a valid URL may not specify the HTTP
> protocol http:// so further validation may be required to determine the
> URL uses
> an expected protocol, e.g. ssh:// or mailto:. Note that the function
> will only
> find ASCII URLs to be valid; internationalized domain names (containing non-
> ASCII characters) will fail.

FILTER_VALIDATE_URL validates URLs, not URIs.

------------------------------------------------------------------------
[2021-08-05 07:00:28] tamas dot nagy0404 at outlook dot com

Description:
------------
Hi,

Looks like the filter_var('urn:isbn:0451450523', FILTER_VALIDATE_URL);
function does not validate the urn: type of URIs properly.

The "urn:" type of URIs are mentioned by http://www.faqs.org/rfcs/rfc2396.html however the
function just marks as invalid whereas it should validate it according to http://www.faqs.org/rfcs/rfc2141.html that is
referenced from the RFC2396. 

Related comment: https://www.php.net/manual/en/filter.filters.validate.php#110411

Tests: https://3v4l.org/SOd9X#veol

Test script:
---------------
https://3v4l.org/SOd9X#veol

Expected result:
----------------
I would expect to validate urn: URIs to be validated properly according to http://www.faqs.org/rfcs/rfc2141.html



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81332&edit=1


Thread (5 messages)

« previous php.bugs (#235606) next »