Doc #60846 [Opn->Fbk]: Warn that base64_encode needs urlencode in query string parameters
| From: | rasmus@php.net | Date: | Tue, 24 Jan 2012 17:00:49 +0000 |
| Subject: | Doc #60846 [Opn->Fbk]: Warn that base64_encode needs urlencode in query string parameters | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7846@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60846&edit=1
ID: 60846
Updated by: rasmus@php.net
Reported by: joeyadams3 dot 14159 at gmail dot com
Summary: Warn that base64_encode needs urlencode in query
string parameters
-Status: Open
+Status: Feedback
Type: Documentation Problem
Package: *URL Functions
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Sounds like a good idea. Go to the base64_encode manual page and look for the
little [edit] link and you can edit the page.
Previous Comments:
------------------------------------------------------------------------
[2012-01-23 06:03:34] joeyadams3 dot 14159 at gmail dot com
Description:
------------
One of the characters used in MIME Base64 is '+', which is a special character in URL
query strings.
A common mistake is to use the result of base64_encode directly in a URL. Example:
http://docs.joomla.org/index.php?title=How_do_you_redirect_users_after_a_successful_login%3F&oldid=36843
I even found some instances of this mistake in Joomla itself. I noticed it while troubleshooting an
issue where com_login would send the user to a useless page saying "Welcome to the registered
user area of our site."
I believe the documentation for base64_encode should warn about this. See the test script for
examples.
Test script:
---------------
<?php
$return = "http://localhost/~me";
// WRONG. This will be decoded server-side as "http://localhost/[Y"
$url = "login?return=" . base64_encode($return);
// Base64 must be URL-encoded when used in a URL, because it can contain '+'
// characters.
$url = "login?return=" . urlencode(base64_encode($return));
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=60846&edit=1