Description
If a value provided to validation rule is incorrect UTF-8,
then formatting of error messages for some rules will fail and original template message will be returned, without formatting.
For example, rule:
'field' => new Regex(
pattern: '/^abc$/u',
),
input field's value: "\x80" (it is invalid UTF-8)
result error: "{Property} not valid.", instead of "Field not valid."
This happens because for some rules value is passed to formatting along with other parameters:
['property' => ..., 'Property' => ..., 'value' => ...]
IntlMessageFormatter::format() fails to format it and returns false, and not formatted message used as fallback,
it fails because underlying intl ext (ICU library) strictly requires all incoming payload text to be valid UTF-8 or UTF-16
But error message should not be corrupted because of user input, value can be sanitized like this:
mb_substitute_character(0xFFFD);
$clean = mb_convert_encoding($dirty, 'UTF-8', 'UTF-8');
0xFFFD is official Unicode Replacement Character: �
or function from intl ext can be used for same result,
it is better because mb_substitute_character() sets global state
$clean = UConverter::transcode($dirty, 'UTF-8', 'UTF-8');
https://www.php.net/manual/en/uconverter.transcode.php
If the input string contains a sequence of bytes which is not valid in the encoding specified by fromEncoding, they are replaced by Unicode code point U+FFFD (Replacement Character) before converting to toEncoding.
Package version
No response
PHP version
No response
Description
If a value provided to validation rule is incorrect UTF-8,
then formatting of error messages for some rules will fail and original template message will be returned, without formatting.
For example, rule:
input field's value:
"\x80"(it is invalid UTF-8)result error:
"{Property} not valid.", instead of"Field not valid."This happens because for some rules value is passed to formatting along with other parameters:
['property' => ..., 'Property' => ..., 'value' => ...]IntlMessageFormatter::format()fails to format it and returns false, and not formatted message used as fallback,it fails because underlying intl ext (ICU library) strictly requires all incoming payload text to be valid UTF-8 or UTF-16
But error message should not be corrupted because of user input, value can be sanitized like this:
0xFFFD is official Unicode Replacement Character: �
or function from intl ext can be used for same result,
it is better because mb_substitute_character() sets global state
https://www.php.net/manual/en/uconverter.transcode.php
Package version
No response
PHP version
No response