Skip to content

Replace deprecated FILTER_SANITIZE_STRING with FILTER_UNSAFE_RAW - #9

Merged
kktsvetkov merged 1 commit into
fuko-php:masterfrom
MIIXknikolov:fix/filter-sanitize-string-deprecated
Sep 24, 2026
Merged

kktsvetkov merged 1 commit into
fuko-php:masterfrom
MIIXknikolov:fix/filter-sanitize-string-deprecated

Conversation

@MIIXknikolov

Copy link
Copy Markdown
Contributor

FILTER_SANITIZE_STRING is deprecated as of PHP 8.1. Besides raising deprecation notices, it also altered the collected input values (stripping/encoding characters), which could prevent the original sensitive value from being matched and redacted in log output.

FILTER_UNSAFE_RAW performs no filtering and returns the raw value, which is the desired behaviour here: the collected values are used for matching and masking, not for sanitising.

FILTER_SANITIZE_STRING is deprecated as of PHP 8.1. Besides raising
deprecation notices, it also altered the collected input values
(stripping/encoding characters), which could prevent the original
sensitive value from being matched and redacted in log output.

FILTER_UNSAFE_RAW performs no filtering and returns the raw value,
which is the desired behaviour here: the collected values are used
for matching and masking, not for sanitising.
@kktsvetkov
kktsvetkov merged commit 6d46ef1 into fuko-php:master Sep 24, 2026
1 check passed
@kktsvetkov

Copy link
Copy Markdown
Member

Changes are included in 1.1.4

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants