Bug->Doc #42718 [Opn]: filter.default_flags are ignored if filter.default = unsafe_raw

From: Date: Wed, 11 Aug 2021 11:00:32 +0000
Subject: Bug->Doc #42718 [Opn]: filter.default_flags are ignored if filter.default = unsafe_raw
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-19061@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42718&edit=1 ID: 42718 Updated by: cmb@php.net Reported by: arnaud dot lb at gmail dot com -Summary: FILTER_UNSAFE_RAW not applied when configured as default filter, even with flags +Summary: filter.default_flags are ignored if filter.default = unsafe_raw Status: Open -Type: Bug +Type: Documentation Problem Package: Filter related Operating System: * PHP Version: 5.*, 6CVS (2009-04-30) Block user comment: N Private report: N New Comment: > Maybe fixing the manual is a simple solution? At this point in time, I have to agree, although that makes filter.default practically useless. Previous Comments: ------------------------------------------------------------------------ [2020-12-21 05:07:16] sji at sj-i dot dev I've confirmed that this still occurs on 8.0.1 . filter.default_flags are ignored if filter.default = unsafe_raw. Because the behavior is being kept this way for 13 years, I'm not confident whether just enabling the filtering makes sense. Maybe fixing the manual is a simple solution? If there are needs for this specific feature, adding another filter that can be used in filter.default with filter.default_flags would be good... ------------------------------------------------------------------------ [2010-04-05 18:21:03] rasmus@php.net We should figure out what we want here. Do we want to allow default flags to be applied with the unsafe_raw filter or not? ------------------------------------------------------------------------ [2008-12-06 19:20:34] pajoye@php.net Yes, revert was the best option for now. I will dig into it on Monday and re read the discussions about that (there was some discussions about this whole thing when we added filter to core). ------------------------------------------------------------------------ [2008-12-06 19:17:09] lbarnaud@php.net > That's wrong This is exactly what you said one year ago, just before it was demonstrated that FILTER_UNSAFE_RAW actually does something (according to documentation, code, and examples), and the bug has been assigned to you. That said, I'm not rejecting the fault on anyone, and the important is to revert, which is done. ------------------------------------------------------------------------ [2008-12-06 18:25:20] pajoye@php.net ooch. I did not catch in this bug before, but there is a major misunderstanding in the first comment. "The unsafe_raw filter does nothing by default, but it can "optionally strip or encode special characters", and it is the only filter which is able to do that without doing any other filtering." That's wrong. UNSAFE_RAW, the key word here is RAW. It means that the data is returned unfiltered, without flag, nothing, nada. If this behavior has been changed then please revert it. I did not check if it is present in 5.2.7 (it seems to be, as said in this report or another), that may require a quick fix release (Ilia?). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=42718 -- Edit this bug report at https://bugs.php.net/bug.php?id=42718&edit=1

« previous php.doc.bugs (#19061) next »