Formating of error messages will fail for some rules if input is invalid UTF-8
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
Direzione di ricerca
Start by reproducing the Regex rule example with the invalid UTF-8 value "\x80", then trace the error-message formatting path that passes the value to IntlMessageFormatter::format(). Verify the fix by confirming that the result is formatted as "Field not valid." rather than returning the unformatted template, and add coverage for the invalid input if the existing test structure provides a suitable place.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
If a value provided to validation rule is incorrect UTF-8,
then formatting of error messages for some rules will fail and original template message will be returned, without formatting.
For example, rule:
'field' => new Regex(
pattern: '/^abc$/u',
),
input field's value: "\x80" (it is invalid UTF-8)
result error: "{Property} not valid.", instead of "Field not valid."
This happens because for some rules value is passed to formatting along with other parameters:
['property' => ..., 'Property' => ..., 'value' => ...]
IntlMessageFormatter::format() fails to format it and returns false, and not formatted message used as fallback,
it fails because underlying intl ext (ICU library) strictly requires all incoming payload text to be valid UTF-8 or UTF-16
But error message should not be corrupted because of user input, value can be sanitized like this:
mb_substitute_character(0xFFFD);
$clean = mb_convert_encoding($dirty, 'UTF-8', 'UTF-8');
0xFFFD is official Unicode Replacement Character: �
or function from intl ext can be used for same result,
it is better because mb_substitute_character() sets global state
$clean = UConverter::transcode($dirty, 'UTF-8', 'UTF-8');
https://www.php.net/manual/en/uconverter.transcode.php
If the input string contains a sequence of bytes which is not valid in the encoding specified by fromEncoding, they are replaced by Unicode code point U+FFFD (Replacement Character) before converting to toEncoding.
Package version
No response
PHP version
No response
- Lingua principale
- PHP
- Stelle
- 167
- Fork
- 47
- Merge medio
- 1g 16h
- PR unite (30g)
- 4
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di yiisoft/validator
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 65/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
-
Multibyte trim supportAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
-
Make File size validation messages human-readableForse di nuovo libera @samdark l’ha presa 117 giorni fa e non c’è nessuna pull request aperta. Apertatype:bug
Tutte le issue di yiisoft/validator
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Awaiting Triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
WordPress/two-factor#1008 ·
I maintainer di solito rispondono entro 1 giorno
-
sync-en
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno