Bug #69250 [Opn->Csd]: PHP FPM status report produces invalid JSON and XML
| From: | bukka@php.net | Date: | Fri, 16 Jun 2023 17:50:36 +0000 |
| Subject: | Bug #69250 [Opn->Csd]: PHP FPM status report produces invalid JSON and XML | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-244713@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69250&edit=1
ID: 69250
Updated by: bukka@php.net
Reported by: s dot greiner at cadenas dot de
Summary: PHP FPM status report produces invalid JSON and XML
-Status: Open
+Status: Closed
Type: Bug
Package: FPM related
Operating System: any
PHP Version: 5.5.22
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
So the JSON request uri escaping was implemented in https://github.com/php/php-src/commit/5e64ead64ab5eaba5d62847483c847c1836171d7
and it is part of just released PHP 8.1.20.
I left this open before to also check the XML part which I just did. This is already escaped for
request-uri in the same way as HTML format. Using CDATA is not necessary here and cannot be
considered as a bug and escaping result is the same for the parsers.
The only part that actually is worth to look at more into is the mentioned script. This applies on
JSON as well and I have just created a ticket specifically for that: https://github.com/php/php-src/issues/11464
and will be looked at later as it is not a major issue really.
Previous Comments:
------------------------------------------------------------------------
[2015-03-17 19:27:43] s dot greiner at cadenas dot de
Description:
------------
Open the Status Page of FPM, for example:
http://my.server.ip/status-php-fpm?json&full&testparam=\a\b\c
Take the "json" output of it and validate it -> it will fail because any backslash is
not escaped in the "request uri" property.
According to http://json.org/string.gif every unicode
character is allowed in a string but no " or \ or a control character. They have to be escaped.
The same problem may occur with the "script" property.
Regarding XML output: the text nodes of <request-uri> and <script> should be wrapped in
CDATA sections.
This erroneous behavior applies to every request not only the ones to the status page, for example a
request to http://my.server.ip/mywebsite/something?path=foo\bar
will make the status page to produce invalid output.
Expected result:
----------------
"processes":[
{
"pid":2432,
"state":"Idle",
"start time":1425579888,
"start since":1039595,
"requests":1523,
"request duration":614,
"request method":"GET",
"request uri":"/php-status?json&full&testparam=\\a\\b\\c",
"content length":0,
"user":"-",
"script":"-",
"last request cpu":0.00,
"last request memory":262144
},
...
Actual result:
--------------
"processes":[
{
"pid":2432,
"state":"Idle",
"start time":1425579888,
"start since":1039595,
"requests":1523,
"request duration":614,
"request method":"GET",
"request uri":"/php-status?json&full&testparam=\a\b\c",
"content length":0,
"user":"-",
"script":"-",
"last request cpu":0.00,
"last request memory":262144
},
...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69250&edit=1