This RFC proposes improving error handling in the Filter extension when invalid option values are supplied to filter_var(), filter_var_array(), filter_input(), and filter_input_array().
Currently, some option values are implicitly converted to integers. In particular, an invalid type such as an array supplied as flags may be silently converted instead of producing a clear error.
This proposal introduces a gradual migration path: PHP 8.7 will emit a deprecation notice for these invalid values, while PHP 8.8 will throw a ValueError instead.
The Filter extension will no longer silently accept invalid values for options that are required to be integers.
The proposal applies to integer option handling in: filter_var, filter_var_array, filter_input, filter_input_array
E_DEPRECATED notice.ValueError.The following examples demonstrate the proposed behavior for invalid option types and invalid filter/flag values across the affected Filter APIs.
An invalid string is supplied as flags:
<?php // E_DEPRECATED: filter_var: flags must be of type int, string given in %s filter_var( '123', FILTER_VALIDATE_INT, [ 'flags' => 'abc', // Invalid flag type ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
An invalid integer is supplied as flags:
<?php // E_DEPRECATED: filter_var: Unknown flags with ID 10050 in %s filter_var( '123', FILTER_VALIDATE_INT, [ 'flags' => 10050, // Invalid flag value ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
An invalid string is supplied as flags:
<?php // E_DEPRECATED: filter_var_array: flags must be of type int, string given in %s filter_var_array( ['a' => '123'], [ 'a' => [ 'filter' => FILTER_VALIDATE_INT, 'flags' => 'abc', // Invalid flag type ], ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
An invalid integer is supplied as flags:
<?php // E_DEPRECATED: filter_var_array: Unknown flags with ID 10050 in %s filter_var_array( ['a' => '123'], [ 'a' => [ 'filter' => FILTER_VALIDATE_INT, 'flags' => 10050, // Invalid flag value ], ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
The following example uses $_GET['a'] as the input value:
<?php // E_DEPRECATED: filter_input: flags must be of type int, string given in %s filter_input( INPUT_GET, 'a', FILTER_VALIDATE_INT, [ 'flags' => 'abc', // Invalid flag type ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice.
In PHP 8.8, this will throw a ValueError.
An invalid integer is supplied as flags:
<?php // E_DEPRECATED: filter_input: Unknown flags with ID 10050 in %s filter_input( INPUT_GET, 'a', FILTER_VALIDATE_INT, [ 'flags' => 10050, // Invalid flag value ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
The following example uses $_GET['a'] as the input value:
<?php // E_DEPRECATED: filter_input_array: filter must be of type int, string given in %s filter_input_array( INPUT_GET, [ 'a' => [ 'filter' => 'abc', // Invalid filter type 'flags' => FILTER_FLAG_ALLOW_OCTAL ], ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
An invalid integer is supplied as filter:
<?php // E_DEPRECATED: filter_input_array: Unknown filter with ID 10050 in %s filter_input_array( INPUT_GET, [ 'a' => [ 'filter' => 10050, // Invalid filter value 'flags' => FILTER_FLAG_ALLOW_OCTAL, ], ] ); ?>
In PHP 8.7, this emits an E_DEPRECATED notice:
In PHP 8.8, this will throw a ValueError.
Applications that pass values of an invalid type to Filter options may be affected.
In particular, applications relying on implicit conversion of arrays or other invalid values to integers will need to change those values to the appropriate integer constants.
PHP 8.7: Deprecation notice emitted. PHP 8.8: Upgraded to ValueError.
IDEs and static analysis tools may benefit from the more explicit behavior because invalid option values will no longer be silently accepted.
Static analyzers may eventually detect invalid option types and report them before runtime.
None
None
None at present.
This RFC is limited to invalid integer-valued filter and flags options.
Pick a title that reflects the concrete choice people will vote on.
Please consult the php/policies repository for the current voting guidelines.
Primary Vote requiring a 2/3 majority to accept the RFC:
Implementation and PHPT tests: TBD.
* 2026-10-03: Initial RFC draft.