[php-src] Issue #13044: exception and error handlers not called from within ob_start callback
| From: | kkmuffme | Date: | Thu, 28 Dec 2023 21:50:51 +0000 |
| Subject: | [php-src] Issue #13044: exception and error handlers not called from within ob_start callback | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-246152@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/13044
Author: kkmuffme
### Description
The following code:
```php
<?php
function log_it($type, $message) {
file_put_contents('/a.log', $message);
}
function log_it_exception($e) {
file_put_contents('/a.log', $e->getMessage());
}
set_error_handler('log_it');
set_exception_handler('log_it_exception');
function foo($arg) {
some_func($arg);
// same with exceptions
//throw new Exception('message');
return $arg;
}
ob_start('foo');
echo 'this is your API key';
```
Resulted in this output:
```
```
But I expected this output instead:
```
a.log should have been created
```
It seems the error/exception handlers are not called if the error occurs inside a
ob_start callback function, the default PHP error handler is called instead.
I couldn't find this to be documented anywhere and this is something that should get fixed, as
this can cause leaking of PII or secrets into the standard error log, which is normally prevented
when using custom error handlers.
### PHP Version
8.3 (error exists in previous versions too)
### Operating System
_No response_