Skip to content

Formating of error messages will fail for some rules if input is invalid UTF-8 #825

Description

@jettero777

Description

If a value provided to validation rule is incorrect UTF-8,
then formatting of error messages for some rules will fail and original template message will be returned, without formatting.

For example, rule:

'field' => new Regex(
    pattern: '/^abc$/u',
),

input field's value: "\x80" (it is invalid UTF-8)

result error: "{Property} not valid.", instead of "Field not valid."

This happens because for some rules value is passed to formatting along with other parameters:
['property' => ..., 'Property' => ..., 'value' => ...]

IntlMessageFormatter::format() fails to format it and returns false, and not formatted message used as fallback,
it fails because underlying intl ext (ICU library) strictly requires all incoming payload text to be valid UTF-8 or UTF-16

But error message should not be corrupted because of user input, value can be sanitized like this:

mb_substitute_character(0xFFFD); 
$clean = mb_convert_encoding($dirty, 'UTF-8', 'UTF-8'); 

0xFFFD is official Unicode Replacement Character: �

or function from intl ext can be used for same result,
it is better because mb_substitute_character() sets global state

$clean = UConverter::transcode($dirty, 'UTF-8', 'UTF-8');

https://www.php.net/manual/en/uconverter.transcode.php

If the input string contains a sequence of bytes which is not valid in the encoding specified by fromEncoding, they are replaced by Unicode code point U+FFFD (Replacement Character) before converting to toEncoding.

Package version

No response

PHP version

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions