php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #44583 base64_decode: innaccurate documentation for $strict argument
Submitted: 2008-03-31 16:03 UTC Modified: 2008-11-07 10:28 UTC
From: robin_fernandes at uk dot ibm dot com Assigned:
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: Windows
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: robin_fernandes at uk dot ibm dot com
New email:
PHP Version: OS:

 

 [2008-03-31 16:03 UTC] robin_fernandes at uk dot ibm dot com
Description:
------------
In the doc for base64_decode(), the description of the $strict parameter reads:
"Returns FALSE if input contains space or some other separator."
 
In fact, the return value of base64_decode() is not affected by spaces or other white-space chars, regardless of the $strict flag. It is, however, affected by other chars outside of the base64 alphabet. See reproduce code.

The implementation in base64.c suggests this is intentional:
if ((!strict && ch < 0) || ch == -1) { /* a space or some other separator character, we simply skip over */
   continue;
} 

A better description for the $strict param would be:
 "When true, base64_decode() will return false if the data contains a non-whitespace character outside of the base64 alphabet. When false, all characters outside of the base64 alphabet are simply ignored."

 
FYI, here's what RFC 2045 (referred to in the doc) has to say about how the decoder should deal with chars outside of the base64 alphabet:

"All line breaks or other characters not found in Table 1 must be ignored by decoding software.  In base64 data, characters other than those in Table 1, line breaks, and other white space probably indicate a transmission error, about which a warning message or even a message rejection might be appropriate under some circumstances."



Reproduce code:
---------------
<?php
echo "Whitespace does not affect base64_decode, even with \$strict===true:\n";
$noWhiteSpace = "aGVsbG8gd29ybGQh";
var_dump(base64_decode($noWhiteSpace, false));
var_dump(base64_decode($noWhiteSpace, true));
$withWhiteSpace = "a GVs   bG8gd2
		 				9ybGQh";
var_dump(base64_decode($withWhiteSpace, false));
var_dump(base64_decode($withWhiteSpace, true));

echo "\n\nOther chars outside the base64 alphabet are ignored when \$strict===false, but cause failure with \$strict===true:\n";
$badChars = $noWhiteSpace . '*';
var_dump(base64_decode($badChars, false));
var_dump(base64_decode($badChars, true));
?>


Expected result:
----------------
n/a

Actual result:
--------------
Whitespace does not affect base64_decode, even with $strict===true:
string(12) "hello world!"
string(12) "hello world!"
string(12) "hello world!"
string(12) "hello world!"


Other chars outside the base64 alphabet are ignored when $strict===false, but cause failure with $strict===true:
string(12) "hello world!"
bool(false)


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2008-11-07 10:28 UTC] vrana@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

"Returns FALSE if input contains character from outside the base64 alphabet."
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 20:00:02 2026 UTC