|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Request #71576 FILTER_VALIDATE_URL uses an obsolete URI RFC
Submitted: 2016-02-12 15:33 UTC Modified: -
Avg. Score:5.0 ± 0.0
Reproduced:1 of 2 (50.0%)
Same Version:0 (0.0%)
Same OS:1 (100.0%)
From: apokryfos84 at gmail dot com Assigned:
Status: Open Package: Filter related
PHP Version: 5.6.18 OS: Linux
Private report: No CVE-ID: None
Have you experienced this issue?
Rate the importance of this bug to you:

 [2016-02-12 15:33 UTC] apokryfos84 at gmail dot com
According to

"Validates value as URL (according to ยป"

However RFC 2396 has been made obsolete by RFC 3986. This results in several valid RFC 3986 URIs to not validate correctly, (e.g. protocol agnostic URLs). 

Test script:
echo filter_var("",FILTER_VALIDATE_URL)?"yes":"no";
// Echoes yes

echo filter_var("//",FILTER_VALIDATE_URL)?"yes":"no";
// Echoes no but should echo yes as per section 4.2 of RFC 3986


Add a Patch

Pull Requests

Add a Pull Request

PHP Copyright © 2001-2024 The PHP Group
All rights reserved.
Last updated: Thu Feb 29 12:01:27 2024 UTC