Bug #78984 [Asn]: DateTimeZone accepting invalid UTC timezones
| From: | derick@php.net | Date: | Wed, 18 Aug 2021 19:31:15 +0000 |
| Subject: | Bug #78984 [Asn]: DateTimeZone accepting invalid UTC timezones | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235947@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78984&edit=1
ID: 78984
Updated by: derick@php.net
Reported by: eu+php at redrat dot com dot br
Summary: DateTimeZone accepting invalid UTC timezones
Status: Assigned
Type: Bug
Package: Date/time related
Operating System: Linux
PHP Version: 7.4.0
Assigned To: derick
Block user comment: N
Private report: N
New Comment:
This is fixed for PHP 8 and later.
Previous Comments:
------------------------------------------------------------------------
[2020-02-20 08:06:33] a at b dot c dot de
"but today UTC have only timezone between -12 and +12 and construct is accepting any
number"
In fixing this, remember that '+1345' is a legitimate UTC offset that is in actual use
(Chatham Islands Daylight Saving).
------------------------------------------------------------------------
[2019-12-17 23:12:24] carusogabriel@php.net
Looks like this was a feature request: #45528
Introduced via https://github.com/php/php-src/commit/d676396435.
------------------------------------------------------------------------
[2019-12-17 19:14:11] eu+php at redrat dot com dot br
Description:
------------
Today, object \DateTimeZone accepts various timezone format in your construct. One option to
instantiate this is using UTC formats like "-3" or "+5", but today UTC have only
timezone between -12 and +12 and construct is accepting any number, like in test script.
Expected result if you define invalid UTC timezone is fatal error, like when you set other unknown
or bad timezone, as described in php_date.c#L3484, but today this object is accepting any integer
value and causes mistakes in date time operations.
Test script:
---------------
<?php
var_dump(
new \DateTimeZone('-3'),
new \DateTimeZone('+3'),
new \DateTimeZone('+30157')
);
Expected result:
----------------
Fatal error: Uncaught Exception: DateTimeZone::__construct(): Unknown or bad timezone (+30157) in
%script%
Actual result:
--------------
object(DateTimeZone)#1 (2) {
["timezone_type"]=>
int(1)
["timezone"]=>
string(6) "-03:00"
}
object(DateTimeZone)#2 (2) {
["timezone_type"]=>
int(1)
["timezone"]=>
string(6) "+03:00"
}
object(DateTimeZone)#3 (2) {
["timezone_type"]=>
int(1)
["timezone"]=>
string(9) "+30157eZ"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78984&edit=1