Bug->Doc #69234 [Opn]: Escaped single quotes within double quotes not recognized
| From: | requinix@php.net | Date: | Fri, 13 Mar 2015 02:16:07 +0000 |
| Subject: | Bug->Doc #69234 [Opn]: Escaped single quotes within double quotes not recognized | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11999@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69234&edit=1
ID: 69234
Updated by: requinix@php.net
Reported by: chrisdmiddleton at gmail dot com
Summary: Escaped single quotes within double quotes not
recognized
Status: Open
-Type: Bug
+Type: Documentation Problem
-Package: *General Issues
+Package: Scripting Engine problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
\' and \" are about inserting the string delimiter character. The consistency is that
'\"' and "\'" both retain their backslashes.
And as you quoted,
>As in single quoted strings, escaping any other character [not included in the
>above table] will result in the backslash being printed too.
Do you feel like the documentation should explicitly point out that "escaping" the
opposite quote character will keep the backslash?
Previous Comments:
------------------------------------------------------------------------
[2015-03-12 22:36:19] chrisdmiddleton at gmail dot com
I see now that the behavior is somewhat consistent, in the sense that the characters which are
escapable are the *minimum* set of characters. (Since you don't need the backslash for single
quotes in double quotes, why provide it...) But the behavior is somewhat counterintuitive and the
documentation should at least be made clear about this particular case.
------------------------------------------------------------------------
[2015-03-12 22:04:04] chrisdmiddleton at gmail dot com
Description:
------------
When a single quote is backslashed within a single quote (e.g. '\''), the result is a
one-character string consisting of the single quote. However, when the same is done within a
*double*-quoted string, the result is a two character string (\'). This behavior is unexpected,
since in every other way, double quoted strings are *more* interpretive than single quoted strings.
Furthermore, the manual
(http://php.net/manual/en/language.types.string.php#language.types.string.syntax.single) says
> To specify a literal single quote, escape it with a backslash (\). To specify a literal
> backslash, double it (\\).
> ...
> If the string is enclosed in double-quotes ("), PHP will interpret **more** [emphasis
> mine] escape sequences for special characters:
> ...
> As in single quoted strings, escaping any other character will result in the backslash being
> printed too. Before PHP 5.1.1, the backslash in \{$var} had not been printed.
In my mind, this is a bug - namely, the double quoted version should also accept escaped single
quotes, since this true in most other languages:
JavaScript
"\'" === '\'' // ==> true
Python
'\'' == "\'" // ==> true
Ruby
print "\'" == '\'' // ==> true
Perl
#!/usr/bin/perl
print "\'" == '\''; ==> 1 (true)
bash (no, but printf does)
echo "\'" # ==> \'
printf "\'" # ==> '
C/C++
#include <stdio.h>
int main (void) {
printf("\'"); // ==> '
return 0;
}
Java
public class Temp {
public static void main (String[] args) {
System.out.println("\'"); // ==> '
}
}
However, if this is a bug that has existed for a long time (and not intentional), then changing it
might break backward compatibility. In any event, the documentation should be made *very* clear
about this issue. In my case, it was causing inappropriately quoted sql, e.g. allowing an attack.
I'm sure that many other people who assume the behavior to be the same as in other languages
might make the same mistake.
Test script:
---------------
<?php
echo "\'";
// Expected: '
// Actual: \'
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69234&edit=1