Re: Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize()
| From: | Ángel González | Date: | Sun, 31 Mar 2013 21:27:59 +0000 |
| Subject: | Re: Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize() | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-66876@lists.php.net to get a copy of this message | ||
On 31/03/13 23:18, ALeX wrote:
>> JSON and serialize() are (inherently) different serialization formats with different
>> use-cases [...]
> Yes, and json requires that all strings (including the keys) has to be
> valid utf-8, and I'm sure that's not always the case (serialize can
> use binary data in both places).
Yes, it is a problem.
> var_dump(json_encode("\xe1 - \xc3\xa1"));
> PHP Warning: json_encode(): Invalid UTF-8 sequence in argument in php
> shell code on line 1
> string(4) "null"
In a perfect world, all your input is utf-8, but sometimes what you get
is in a different encoding...
(and you still want to store it as-it-came in the first layer)