Edit report at https://bugs.php.net/bug.php?id=80502&edit=1
ID: 80502
Comment by: craig at craigfrancis dot co dot uk
Reported by: craig at craigfrancis dot co dot uk
Summary: Comparison of empty string to 0
Status: Verified
Type: Documentation Problem
Package: *General Issues
Operating System: N/A
PHP Version: 8.0.0
Block user comment: N
Private report: N
New Comment:
https://www.php.net/manual/en/language.operators.comparison.php
Operand 1: string, resource, int or float
Operand 2: string, resource, int or float
Result: Translate strings and resources to numbers, usual math
I have a horrible feeling this change is going to cause issues, as PHP is typically working with
user input from web forms, where the GET/POST values provided are strings, same with many other
sources (e.g. fgetcsv).
Previous Comments:
------------------------------------------------------------------------
[2020-12-10 12:49:08] cmb@php.net
Yes, that is indeed a consequence of that RFC. Since the empty
string is not a well-formed numeric string, a string comparison is
done, and the empty string is less than any other string. The
migration guide should not only mention == comparision, but the
other affected operations as well. And of course the respective
documentation in the manual proper needs to be updated.
------------------------------------------------------------------------
[2020-12-10 12:27:28] craig at craigfrancis dot co dot uk
And the same with ('' == 0)... PHP 7 this would be true, PHP 8 it's false.
While I appreciate that's supposed to be false with ('' === 0), the double equals
comparison operator is supposed to be equal "after type juggling".
------------------------------------------------------------------------
[2020-12-10 12:18:56] craig at craigfrancis dot co dot uk
Description:
------------
Maybe related to RFC "string_to_number_comparison"?
In PHP 7 the comparison ('' < 0) would convert the empty string to 0, then return
false.
But in PHP 8.0.0, the empty string is now considered less-than 0?
Common issue for HTML forms, which provide all values as strings, and a blank number field is
effectively seen as 0 - e.g. entering a time with separate fields (hours and minutes), and the user
does not enter a value in the seconds field... yes, you could cast the value to an integer, but a
lot of websites out there don't.
Test script:
---------------
var_export([
('' < 0),
('1' < 0),
('0' < 0),
]);
Expected result:
----------------
array ( 0 => false, 1 => false, 2 => false, )
Actual result:
--------------
array ( 0 => true, 1 => false, 2 => false, )
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80502&edit=1