Bug->Doc #68296 [Opn->Ver]: \n in path with parse_url() converts to underscore

From: Date: Mon, 05 Aug 2019 17:31:10 +0000
Subject: Bug->Doc #68296 [Opn->Ver]: \n in path with parse_url() converts to underscore
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-16859@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68296&edit=1 ID: 68296 Updated by: cmb@php.net Reported by: dave at lyte dot id dot au Summary: \n in path with parse_url() converts to underscore -Status: Open +Status: Verified -Type: Bug +Type: Documentation Problem Package: URL related Operating System: OS X PHP Version: 5.4.34 Block user comment: N Private report: N New Comment: This is not a bug, but rather deliberate albeit undocumented behavior, namely that all control characters in a string passed to parse_url() are replaced by underscores[1]. Therefore I'm changing to doc problem. If you want to have that behavior changed, feel free to start the RFC process[2]. [1] <https://github.com/php/php-src/blob/6326717dccf9e85dc41b3778692b790e2501fb2a/ext/standard/url.c#L59> [2] <https://wiki.php.net/rfc/howto> Previous Comments: ------------------------------------------------------------------------ [2018-01-11 20:25:31] gonzad26 at gmail dot com Pardon me, bug still in PHP 7.1.7. ------------------------------------------------------------------------ [2018-01-11 19:05:15] spam2 at rhsoft dot net besides PHP5 is EOL what do you expect? garbage in, garbage out! control chars don't belong into a url - it's that simple and if you don't sanitze and validate your input data be happy that someone does what do you think happens with null chars and freinds if you concat your remote URL based on userinput and obviously don't care about handle untrusted data careful? ------------------------------------------------------------------------ [2018-01-11 19:01:02] gonzad26 at gmail dot com The problem still persists in php 5.6. Doing: parse_url($path,PHP_URL_HOST); if $path has a "\n" parse_url returns and _ where the \n was. ------------------------------------------------------------------------ [2016-01-15 08:11:46] simonsimcity at gmail dot com Sorry, I meant related to #52923 ------------------------------------------------------------------------ [2016-01-15 08:11:08] simonsimcity at gmail dot com Is related to #68296 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68296 -- Edit this bug report at https://bugs.php.net/bug.php?id=68296&edit=1

« previous php.doc.bugs (#16859) next »