Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Validator] Update regular expression in URL validator#62028

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged

Conversation

@mjaschen
Copy link
Contributor

@mjaschenmjaschen commentedOct 10, 2025
edited by nicolas-grekas
Loading

QA
Branch?6.4
Bug fix?yes
New feature?no
Deprecations?no
Issues-
LicenseMIT

TheUrlValidator::validate() method currently fails for some valid URLs, particularly URLs containing login data with special characters.

Example failing case:

https://user-123:foo+bar-baz@example.com/path/file.txt.gz

The current regular expression only accepts a subset of allowed characters in the userinfo part of the URL, seeUrlValidator.php:26.

Changes in this pull request:

  • Update the regular expression inUrlValidator::PATTERN to support all characters permitted in theuserinfo part of a URL according toRFC 3986.
  • remove unneeded escaping in regular expression character class ([\_\.][_.])
  • Add new test cases covering all special characters in theuserinfo part of URLs.

References:

  • RFC 3986 describing: Uniform Resource Identifier (URI) Generic Syntax
  • Appendix A, “Collected ABNF for URI”

Relevant ABNF foruserinfo in URIs:

userinfo      = *( unreserved / pct-encoded / sub-delims / ":" )unreserved    = ALPHA / DIGIT / "-" / "." / "_" / "~"pct-encoded   = "%" HEXDIG HEXDIGsub-delims    = "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "="

@carsonbot
Copy link

Hey!

I see that this is your first PR. That is great! Welcome!

Symfony has acontribution guide which I suggest you to read.

In short:

  • Always add tests
  • Keep backward compatibility (seehttps://symfony.com/bc).
  • Bug fixes must be submitted against the lowest maintained branch where they apply (seehttps://symfony.com/releases)
  • Features and deprecations must be submitted against the 7.4 branch.

Review the GitHub status checks of your pull request and try to solve the reported issues. If some tests are failing, try to see if they are failing because of this change.

When two Symfony core team members approve this change, it will be merged and you will become an official Symfony contributor!
If this PR is merged in a lower version branch, it will be merged up to all maintained branches within a few days.

I am going to sit back now and wait for the reviews.

Cheers!

Carsonbot

@carsonbotcarsonbot changed the titleUpdate regular expression in URL validator Update regular expression in URL validatorOct 10, 2025
@carsonbotcarsonbot changed the title Update regular expression in URL validator[Validator] Update regular expression in URL validatorOct 14, 2025
@nicolas-grekasnicolas-grekas modified the milestones:7.4,6.4Oct 14, 2025
To achieve better compatibility with RFC 3986, the regular expressionwhich validates URLs now allows more characters in the userinfo part.Add test cases; update change log.
Copy link
Member

@nicolas-grekasnicolas-grekas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

I rebased for 6.4 as a bugfix and further tweaked the regex a bit.

{^
(%s):// # protocol
(((?:[\_\.\pL\pN-]|%%[0-9A-Fa-f]{2})+:)?((?:[\_\.\pL\pN-]|%%[0-9A-Fa-f]{2})+)@)? # basic auth
((?:[\pL\pN\-._~!$&'()*+,;=]|%%[0-9A-Fa-f]{2})++(?::(?:[:\pL\pN\-._~!$&'()*+,;=]|%%[0-9A-Fa-f]{2})*+)?@)? # basic auth
Copy link
Member

@nicolas-grekasnicolas-grekasOct 14, 2025
edited
Loading

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

The RFC allows empty user part, so technically we could go with just the following.
But this makes tests fail as we consider userinfo with no username as invalid (http://:pwd@example.com)

Suggested change
((?:[\pL\pN\-._~!$&'()*+,;=]|%%[0-9A-Fa-f]{2})++(?::(?:[:\pL\pN\-._~!$&'()*+,;=]|%%[0-9A-Fa-f]{2})*+)?@)?# basic auth
((?:[:\pL\pN\-._~!$&'()*+,;=]|%%[0-9A-Fa-f]{2})++)@)? # basic auth

(support for basic auth was added 11 years ago in#11601)

@nicolas-grekas
Copy link
Member

Thank you@mjaschen.

mjaschen reacted with heart emoji

@nicolas-grekasnicolas-grekas merged commit68cd755 intosymfony:6.4Oct 16, 2025
11 checks passed
This was referencedOct 28, 2025
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@nicolas-grekasnicolas-grekasnicolas-grekas approved these changes

@lyrixxlyrixxAwaiting requested review from lyrixx

@ycerutoycerutoAwaiting requested review from yceruto

@chalasrchalasrAwaiting requested review from chalasr

@dunglasdunglasAwaiting requested review from dunglas

@xabbuhxabbuhAwaiting requested review from xabbuh

Assignees

No one assigned

Projects

None yet

Milestone

6.4

Development

Successfully merging this pull request may close these issues.

3 participants

@mjaschen@carsonbot@nicolas-grekas

[8]ページ先頭

©2009-2025 Movatter.jp