Re: Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize()

From: Date: Sun, 31 Mar 2013 21:27:59 +0000
Subject: Re: Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize()
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-66876@lists.php.net to get a copy of this message
On 31/03/13 23:18, ALeX wrote: >> JSON and serialize() are (inherently) different serialization formats with different >> use-cases [...] > Yes, and json requires that all strings (including the keys) has to be > valid utf-8, and I'm sure that's not always the case (serialize can > use binary data in both places). Yes, it is a problem. > var_dump(json_encode("\xe1 - \xc3\xa1")); > PHP Warning: json_encode(): Invalid UTF-8 sequence in argument in php > shell code on line 1 > string(4) "null" In a perfect world, all your input is utf-8, but sometimes what you get is in a different encoding... (and you still want to store it as-it-came in the first layer)

« previous php.internals (#66876) next »