Formating of error messages will fail for some rules if input is invalid UTF-8
まだ誰も着手していません。
評価
調査の方向性
Start by reproducing the Regex rule example with the invalid UTF-8 value "\x80", then trace the error-message formatting path that passes the value to IntlMessageFormatter::format(). Verify the fix by confirming that the result is formatted as "Field not valid." rather than returning the unformatted template, and add coverage for the invalid input if the existing test structure provides a suitable place.
索引モデルが issue の本文から書いたものです。
説明
Description
If a value provided to validation rule is incorrect UTF-8,
then formatting of error messages for some rules will fail and original template message will be returned, without formatting.
For example, rule:
'field' => new Regex(
pattern: '/^abc$/u',
),
input field's value: "\x80" (it is invalid UTF-8)
result error: "{Property} not valid.", instead of "Field not valid."
This happens because for some rules value is passed to formatting along with other parameters:
['property' => ..., 'Property' => ..., 'value' => ...]
IntlMessageFormatter::format() fails to format it and returns false, and not formatted message used as fallback,
it fails because underlying intl ext (ICU library) strictly requires all incoming payload text to be valid UTF-8 or UTF-16
But error message should not be corrupted because of user input, value can be sanitized like this:
mb_substitute_character(0xFFFD);
$clean = mb_convert_encoding($dirty, 'UTF-8', 'UTF-8');
0xFFFD is official Unicode Replacement Character: �
or function from intl ext can be used for same result,
it is better because mb_substitute_character() sets global state
$clean = UConverter::transcode($dirty, 'UTF-8', 'UTF-8');
https://www.php.net/manual/en/uconverter.transcode.php
If the input string contains a sequence of bytes which is not valid in the encoding specified by fromEncoding, they are replaced by Unicode code point U+FFFD (Replacement Character) before converting to toEncoding.
Package version
No response
PHP version
No response
- 主要言語
- PHP
- スター
- 167
- フォーク
- 47
- 平均マージ
- 1日 16時間
- マージ済み PR(30日)
- 4
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
yiisoft/validator のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
-
Make File size validation messages human-readable再び着手できるかも @samdark が 118 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンtype:bug
yiisoft/validator の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 2 日以内に返信
-
UX
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
ProfessionalWiki/NeoWiki#1573 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
endoflife-date/endoflife.date#11194 ·
メンテナーはふだん 1 日以内に返信