Bug #70501 [Com]: MAX_FILE_SIZE does not abort upload
| From: | petk@php.net | Date: | Sun, 25 Nov 2018 22:14:29 +0000 |
| Subject: | Bug #70501 [Com]: MAX_FILE_SIZE does not abort upload | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218132@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70501&edit=1
ID: 70501
Comment by: petk@php.net
Reported by: olafvdspek at gmail dot com
Summary: MAX_FILE_SIZE does not abort upload
Status: Open
Type: Bug
Package: *Web Server problem
Operating System: *
PHP Version: 5.6.13
Block user comment: N
Private report: N
New Comment:
Confirming this bug also here. The MAX_FILE_SIZE post data value check is never reached since the
upload_max_file size ini directive is always set (no matter if you comment it out of php.ini it will
be by default 2MB). This hidden value will only work if you set upload_max_filesize to 0 or -1 (like
unsetting it). On top of that, edge case is vulnerable to changing the value on the user side (it is
a hidden field after all and not a setting in the code).
Considering that it has been used in only an extreme edge case for the past several PHP versions and
frameworks don't use it anymore it might be a good idea to remove it or better yet refactor it
in the core code to something that works. Because with current PHP versions the only check that is
done is the upload_max_filesize ini directive on the php side. And, preferably, also a manual check
inside the code on the server side comparing a manual configuration value to a file size of the
uploaded file.
Previous Comments:
------------------------------------------------------------------------
[2016-06-24 18:45:58] cmb@php.net
Indeed, this is quite certainly not a doc bug, see
<https://github.com/php/php-src/blob/php-7.0.8/main/rfc1867.c#L1049-L1053>.
------------------------------------------------------------------------
[2015-09-15 21:38:18] requinix@php.net
As far as I can tell the intention of MAX_FILE_SIZE was to abort the upload, so the fact that files
continue to be uploaded (which I've confirmed happens with PHP 5.5 + Apache 2.4 + mod_php)
seems to be a bug. Perhaps rather than getting rid of something deemed useless, it can be fixed to
work as expected.
------------------------------------------------------------------------
[2015-09-15 11:57:02] olafvdspek at gmail dot com
The value isn't ignored, but it's checked AFTER the entire file was uploaded.
------------------------------------------------------------------------
[2015-09-15 11:54:14] requinix@php.net
The sentence before that is
> The MAX_FILE_SIZE hidden field (measured in bytes) must precede the file input
> field, and its value is the maximum filesize accepted by PHP.
If you have a repro script that has this field appearing before the file input and the value is
still ignored, please share it so the problem can be fixed.
------------------------------------------------------------------------
[2015-09-15 11:06:53] olafvdspek at gmail dot com
Description:
------------
> This form element should always be used as it saves users the trouble of waiting for a big file
> being transferred only to find that it was too large and the transfer failed.
As far as I know this bit is incorrect. It does NOT avoid a too-large file from being uploaded as
the value is only checked AFTER the file was uploaded completely.
http://php.net/manual/en/features.file-upload.post-method.php
IMO MAX_FILE_SIZE is useless and should be dropped entirely.
Test script:
---------------
-
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70501&edit=1