Re: Net_URL Bug #6470

From: Date: Tue, 07 Feb 2006 06:24:59 +0000
Subject: Re: Net_URL Bug #6470
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-41206@lists.php.net to get a copy of this message
Bonjour, I wonder in how many places in pear the same, or at least approaching, goals of validating/correcting URIs is done. We have currently the same discussion in Text_Wiki about the best way to encode complient URLs. You can also take a look in the uri() method from Validate. http://cvs.php.net/viewcvs.cgi/pear/Validate/Validate.php Anyway, I agree the path should be url encoded. About your patch: - why use preg_split ? only to get no empty parts ? Is it not yet done be done by the method resolvePath() ? More generally, I think everything should be done there. - as urlencode treats spaces as +, I wonder if rawurlencode() would not be better complient (%20), but remember *all* not alphanum nore '-_.' will be, perhaps unnecessarly, encoded ( !~*\'()$+&,...) - you accept lonely '%' in path, which I believe not rfc2396 complient. - '?' in path ? - on the countrary I believe '\' *is* allowed - looks like it treats, or should treat only absolute path, is it ? - more generally, it's unclear how and where this method will be called, or I miss something... I would really like some unified method in pear for that, so we don't repeat everywhere the same thing and more important that we act coherently. à+ -- toggg Andrei Railean wrote:
Thanks, Marco. I'm sending a diff to this list as well as submitting it to the bug tracker. The diff is made from the CVS version. Not sure what you mean that bug doesn't really explain the problem. The problem is that the PATH component of the url is never properly encoded and does not have any proper getter functions so all the other packages are forced to use the $path member variable directly. This is what was described in the bug report. In reality, this fix is meant to affect the HTTP_Request package, but instead of putting it there, I chose to modify Net_URL so that the fix is more universal. HTTP_Request needs to be modified as well once (or if) this fix goes through. Thanks. ------------------------------------------------------------------------ Index: URL.php =================================================================== RCS file: /repository/pear/Net_URL/URL.php,v retrieving revision 1.42 diff -w -u -r1.42 URL.php --- URL.php 29 Oct 2005 11:17:56 -0000 1.42 +++ URL.php 6 Feb 2006 23:28:43 -0000 @@ -418,5 +418,47 @@
        $this->port     = is_null($port) ? $this->getStandardPort($protocal) : $port;
    }
+ /** + * Returns encoded path + * + * Result is properly encoded and ready for use in the request. + * Complies with RFC 2396 - Uniform Resource Identifiers (URI): Generic Syntax + * Does not modify the internal state + * + * Code Based on work by: esm-at-baseclass.modulweb.dk + * see: http://baseclass.modulweb.dk/urlvalidator + * + * @return string Path + * @access public + */ + function getEncodedPath() + { + $is_dir = false; + if (strlen($this->path) > 1 && substr($this->path, -1) == '/') { + $is_dir = true; + } + + $path_parts = preg_split('|/|', $this->path, -1, PREG_SPLIT_NO_EMPTY); + + if (empty($path_parts)) { + return '/'; + } + + foreach ($path_parts as $key => $part) { + // Check for % that is NOT an escape sequence || invalid chars + if (preg_match('/%[^a-f0-9]/i', $part) || preg_match('/[^@a-z0-9_.!~*\'()$+&,%:=;?-]/i', $part)) { + $path_parts[$key] = urlencode(urldecode($part)); + } + } + + $path = '/'.implode('/', $path_parts); + + if ($is_dir) { + $path .= '/'; + } + + return $path; + } + } ?> ------------------------------------------------------------------------ On 06/02/2006, at 6:25 PM, Marco Kaiser wrote:
Hi Andrei, you reported bug doenst really explain whats the problem and please provide a better bugfix. use diff to tell the developer where you want to have some changes.


« previous php.pear.dev (#41206) next »