Bug #63808 [Opn->Nab]: FireFox Secure Mode vs Full Path and Filename
Edit report at https://bugs.php.net/bug.php?id=63808&edit=1
ID: 63808
Updated by: aharvey@php.net
Reported by: davisoftaec at gmail dot com
Summary: FireFox Secure Mode vs Full Path and Filename
-Status: Open
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: Ubuntu
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Sorry, but your problem does not imply a bug in PHP itself. For a
list of more appropriate places to ask for help using PHP, please
visit http://www.php.net/support.php as this bug system
is not the
appropriate forum for asking support questions. Due to the volume
of reports we can not explain in detail here why your report is not
a bug. The support channels will be able to provide an explanation
for you.
Thank you for your interest in PHP.
Form file uploads don't work that way, sorry. PHP never gets the full path of the file.
Previous Comments:
------------------------------------------------------------------------
[2012-12-19 19:22:48] davisoftaec at gmail dot com
Description:
------------
Sirs;
I'm developing in serveral versions the oldest is 5.3.2 for Ubuntu.
I found that realpath nor any other function in PHP will return a fullpath/filename.
I originally open a thread on this at:
http://ubuntuforums.org/showthread.php?t=2077379
Then once I discovered it was a FF Secure Mode issue posted it at:
http://forums.mozillazine.org/viewtopic.php?f=7&t=2612465&p=12467081#p12467081
I realize, since the Secure Mode Mandate was announced, not all issues surrounding it have been
addressed.
I wanted to make you aware of this one and if you do not put this correction back into the
"realpath" function, due to the debate over what it should do or be limited to, then give
us a function that addresses this.
The coder should not have to be dealing with issues that are at this level, because the coder does
not know what the default configuration of the users browser will be, so the fix for this must
circumvent any restrictions placed on it by the browser.
If keeping the browser secure is a concern, then a POP-UP message to allow this
"fullpath/filename" variable assignment should appear, to allow the work around to run the
processing correctly.
Thanks!
OldManRiver
Test script:
---------------
<?php
define ('SHOW_ME', 1);
if (SHOW_ME==1) {
foreach ($_POST as $key => $val) {
echo "PK=> $key PV=> $val <br>";
} // end foreach $_POST
foreach ($_GET as $key => $val) {
echo "GK=> $key GV=> $val <br>";
} // end foreach $_POST
} // end if SHOW_ME
?>
<html>
<head>
<script type="text/javascript">
function folder_address() {
var pfile=document.getElementById('pfile');
echo pfile.value;
location.href="<?php echo $_SERVER['PHP_SELF']; ?>?pfile=" +
pfile.value;
}
</script>
</head>
<body onLoad ="folder_address();">
<FORM NAME='realp' METHOD='POST' ACTION="<?php echo
$_SERVER['PHP_SELF']; ?>">
<table align='center' width='50%' border='5'
cellspacing='0' cellpadding='0'>
<tr>
<td> </td>
</tr>
<tr>
<td align='center'>
<div class="fileinputs1">
<!-- input type="file" id="folder_add" name="folder_add">
<input type="hidden" id="folder" name="folder">
<br -->
<input type='file' id='pfile' name='pfile'
value='Browse'>
</div>
<input type='submit' value='Submit'>
</td>
</tr>
</table>
</form>
</body>
</html>
Expected result:
----------------
The entire and complete fullpath and filename of the file on the local or hosted machine.
Actual result:
--------------
only the filename, path is truncated.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63808&edit=1
Thread (3 messages)