PHP 4.0 Bug #6685 Updated: %20 mis-converted in GET mechanism
| From: | waldschrott@php.net | Date: | Tue, 21 Nov 2000 20:37:35 +0000 |
| Subject: | PHP 4.0 Bug #6685 Updated: %20 mis-converted in GET mechanism | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-38852@lists.php.net to get a copy of this message | ||
ID: 6685
Updated by: waldschrott
Reported By: waldschrott@php.net
Status: Analyzed
Bug Type: *General Issues
Assigned To:
Comments:
well why do you think are cased variables needed? why do we
need to be able to use variables containg ä,ö,ü etc.
I'd say escpecially with variable variables this could be
useful in some cases
Previous Comments:
---------------------------------------------------------------------------
[2000-11-21 03:35:41] sniper@php.net
I think that having spaces in variable names is not
a good thing (tm). could someone please explain me
how it would be useful at all?
--Jani
---------------------------------------------------------------------------
[2000-09-16 17:59:27] stas@php.net
On the second though, you _can_ have variables with spaces (actually, you can name variable with
every string you can put into variable), so I don't quite understand the maning of that
variable name translation. Do we really need it? Anybody will have problems if we remove it?
---------------------------------------------------------------------------
[2000-09-12 13:46:32] waldschrott@php.net
since we all (almost) agree that register_globals should be deprecated ASAP and array indices with
spaces are legal and URIs containg QUERYSTRING with them too, well at least the $HTTP_GET_VARS array
should contain the non-converted information, if register_globals=on this mechanism can be applied
for global variables
We shouldn´t obscure URI data.
---------------------------------------------------------------------------
[2000-09-12 13:41:29] stas@php.net
And what would you expect it to do? You cannot have variable names with spaces.
---------------------------------------------------------------------------
[2000-09-12 13:39:37] waldschrott@php.net
I guess this is has the potential to be a serious bug since I think I´m allowed to take any
key/value pairs I want to if encoded correctly, very simple to reproduce
Call a page with this QueryString
?%20asd%20%20=%20asdf (you can replace %20 with + if you want to, same effect)
and look what happened to to the key part of key=value
<?php var_dump($HTTP_GET_VARS); ?>
all leading spaces are stripped, all trailing ones converted to "_" - that really does not
make sense, I don´t know what else is converted with mystic rules, I found these
The only workaround is to access the QueryString directly which seems to be fine (of course)
---------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view the rest of the comments,
please view the bug report online.
Full Bug description available at: http://bugs.php.net/?id=6685