Bug->Doc #73975 [Ver]: parse_url does not decode % escaping of username

From: Date: Tue, 12 Sep 2017 10:49:57 +0000
Subject: Bug->Doc #73975 [Ver]: parse_url does not decode % escaping of username
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14966@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73975&edit=1 ID: 73975 Updated by: cmb@php.net Reported by: trejkaz at trypticon dot org Summary: parse_url does not decode % escaping of username Status: Verified -Type: Bug +Type: Documentation Problem Package: URL related Operating System: macOS PHP Version: 5.6.30 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > It does not look like any component of the URL is url-decoded by > parse_url(). Indeed. Changing to doc bug. Previous Comments: ------------------------------------------------------------------------ [2017-01-23 11:44:06] nikic@php.net It does not look like any component of the URL is url-decoded by parse_url(). While I personally think that parse_url() *ought* to be doing this, changing it at this point would be counter-productive, as client code would have to conditionally decode the result (rather than always decode it), leading to more brittle code. ------------------------------------------------------------------------ [2017-01-23 11:35:21] cmb@php.net Confirmed: <https://3v4l.org/W8DWh>. ------------------------------------------------------------------------ [2017-01-23 02:38:11] trejkaz at trypticon dot org Description: ------------ The userinfo part of a URL can contain %-encoding for characters which otherwise would confuse a URL parser. Thus if your username or password contains, for instance, a @, you would be entering %40 into the URL instead. PHP's parse_url function does not perform decode this encoding, but returns the 'user' and 'pass' values with it as it was in the original URL. Alternatively, if the intent is that this function keeps the encoding in the values, this should be clearly stated in the documentation. It turns out that Drupal is calling this function, seemingly assuming that it is being completely decoded. Test script: --------------- <? var_dump(parse_url('https://user%40name:pass%40word@example.com')); ?> Expected result: ---------------- array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(9) "user@name" ["pass"]=> string(9) "pass@word" } Actual result: -------------- array(4) { ["scheme"]=> string(5) "https" ["host"]=> string(11) "example.com" ["user"]=> string(11) "user%40name" ["pass"]=> string(11) "pass%40word" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73975&edit=1

« previous php.doc.bugs (#14966) next »