Req #55102 [Com]: add parameter to parse_str to avoid sanitizing of root keys
| From: | rok dot kralj at gmail dot com | Date: | Thu, 09 Sep 2021 20:08:32 +0000 |
| Subject: | Req #55102 [Com]: add parameter to parse_str to avoid sanitizing of root keys | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-236515@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55102&edit=1
ID: 55102
Comment by: rok dot kralj at gmail dot com
Reported by: giorgio dot liscio at email dot it
Summary: add parameter to parse_str to avoid sanitizing of
root keys
Status: Open
Type: Feature/Change Request
Package: URL related
Operating System: Irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
This bug has a neat workaround. Just take the root keys, encode them (so dots and other special
characters are hidden), then use parse_str.
You can take the code from here, just attribute it.
https://stackoverflow.com/a/18209799/924109
Previous Comments:
------------------------------------------------------------------------
[2011-07-01 19:02:06] felipe@php.net
Changing to Feature request.
------------------------------------------------------------------------
[2011-07-01 09:31:45] giorgio dot liscio at email dot it
Description:
------------
hi, this is probably an old behavior to make php backward compatible when register_global was
enabled
parse_str("hey all=1",$r); ---> array('hey_all' => '1');
parse_str is now widely used in xmlhttprequest communication and may cause a lot of issues and waste
of time when debugging because we are not able to know how exactly what type of character sanitizing
is made to root keys
yep, only root keys are sanitized because
parse_str("aaa[hey all]=1",$r); ---> array('aaa' => array('hey
all', '1'));
works like expected
so my request is not to change the default behavior of this function (and how $_GET $_POST etc are
populated)
but add another parameter to this function for who wants root keys parsed without sanitizing
void parse_str ( string $str [, array &$arr ] [, bool $bwcompatible = true])
thank you
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55102&edit=1