Re: Net_URL Bug #6470

From: Date: Mon, 06 Feb 2006 23:48:45 +0000
Subject: Re: Net_URL Bug #6470
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-41203@lists.php.net to get a copy of this message
Thanks, Marco. I'm sending a diff to this list as well as submitting it to the bug tracker. The diff is made from the CVS version. Not sure what you mean that bug doesn't really explain the problem. The problem is that the PATH component of the url is never properly encoded and does not have any proper getter functions so all the other packages are forced to use the $path member variable directly. This is what was described in the bug report. In reality, this fix is meant to affect the HTTP_Request package, but instead of putting it there, I chose to modify Net_URL so that the fix is more universal. HTTP_Request needs to be modified as well once (or if) this fix goes through. Thanks.

Index: URL.php =================================================================== RCS file: /repository/pear/Net_URL/URL.php,v retrieving revision 1.42 diff -w -u -r1.42 URL.php --- URL.php 29 Oct 2005 11:17:56 -0000 1.42 +++ URL.php 6 Feb 2006 23:28:43 -0000 @@ -418,5 +418,47 @@ $this->port = is_null($port) ? $this->getStandardPort($protocal) : $port; } + /** + * Returns encoded path + * + * Result is properly encoded and ready for use in the request. + * Complies with RFC 2396 - Uniform Resource Identifiers (URI): Generic Syntax + * Does not modify the internal state + * + * Code Based on work by: esm-at-baseclass.modulweb.dk + * see: http://baseclass.modulweb.dk/urlvalidator + * + * @return string Path + * @access public + */ + function getEncodedPath() + { + $is_dir = false; + if (strlen($this->path) > 1 && substr($this->path, -1) == '/') { + $is_dir = true; + } + + $path_parts = preg_split('|/|', $this->path, -1, PREG_SPLIT_NO_EMPTY); + + if (empty($path_parts)) { + return '/'; + } + + foreach ($path_parts as $key => $part) { + // Check for % that is NOT an escape sequence || invalid chars + if (preg_match('/%[^a-f0-9]/i', $part) || preg_match('/[^@a-z0-9_.!~*\'()$+&,%:=;?-]/i', $part)) { + $path_parts[$key] = urlencode(urldecode($part)); + } + } + + $path = '/'.implode('/', $path_parts); + + if ($is_dir) { + $path .= '/'; + } + + return $path; + } + } ?>
« previous php.pear.dev (#41203) next »