Bug->Doc #74599 [Nab->Opn]: parse_url allows bad characters in the common name

From: Date: Tue, 16 May 2017 01:59:28 +0000
Subject: Bug->Doc #74599 [Nab->Opn]: parse_url allows bad characters in the common name
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14695@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74599&edit=1 ID: 74599 Updated by: requinix@php.net Reported by: bj dot cardon at gmail dot com Summary: parse_url allows bad characters in the common name -Status: Not a bug +Status: Open -Type: Bug +Type: Documentation Problem Package: URL related Operating System: Linux PHP Version: 7.0.19 Block user comment: N Private report: N New Comment: The underscores are only applied to control characters - guaranteed to be invalid everywhere. The docs should clarify that "invalid" does not consider what is allowed in each component. > not parse the URL in a nonsensical way parse_url tries to break the string into pieces in the most reasonable way it can figure. Mostly based on the presence of delimiters. Backslashes don't have significance, unlike : or / or ?, so they're ignored. If you think that a "nonsensical way" is parsing a string without validation then a "sensical way" would be parsing it *with* validation, and parse_url is only designed to do half of that. Parsing with validation is trivial: function parse_valid_url($url, $component = -1) { return filter_var($url, FILTER_VALIDATE_URL) ? parse_url($url, $component) : false; } Previous Comments: ------------------------------------------------------------------------ [2017-05-16 01:37:42] bj dot cardon at gmail dot com On a side note, perhaps returning FALSE is not the actual expected behavior, however I don't think the behavior as it currently exists is ideal for this scenario. ------------------------------------------------------------------------ [2017-05-16 01:31:32] bj dot cardon at gmail dot com I don't need "validation". I need a function that claims to parse a URL to not parse the URL in a nonsensical way. The documentation also says: > Invalid characters are replaced by _ Which is not happening with the invalid character of '\'. ------------------------------------------------------------------------ [2017-05-15 23:56:20] requinix@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php > This function is not meant to validate the given URL, it only breaks it up into > the above listed parts. ------------------------------------------------------------------------ [2017-05-15 18:51:56] bj dot cardon at gmail dot com Description: ------------ As the title says, the parse_url function allows backslashes to be in the hostname part of a URL and considers it valid. You can see the test script below showing this behavior. Test script: --------------- bcardon@bcardon-base:~$ php -a Interactive mode enabled php > $u = parse_url("https://www.example.com\\.google.com"); php > print_r($u); Array ( [scheme] => https [host] => www.example.com\.google.com ) Expected result: ---------------- The expected behavior is that invalid characters (including backslashes) will cause parse_url to return FALSE as with any invalid URL. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74599&edit=1

« previous php.doc.bugs (#14695) next »