Bug #70501 [Com]: MAX_FILE_SIZE does not abort upload

From: Date: Sun, 25 Nov 2018 22:14:29 +0000
Subject: Bug #70501 [Com]: MAX_FILE_SIZE does not abort upload
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218132@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70501&edit=1 ID: 70501 Comment by: petk@php.net Reported by: olafvdspek at gmail dot com Summary: MAX_FILE_SIZE does not abort upload Status: Open Type: Bug Package: *Web Server problem Operating System: * PHP Version: 5.6.13 Block user comment: N Private report: N New Comment: Confirming this bug also here. The MAX_FILE_SIZE post data value check is never reached since the upload_max_file size ini directive is always set (no matter if you comment it out of php.ini it will be by default 2MB). This hidden value will only work if you set upload_max_filesize to 0 or -1 (like unsetting it). On top of that, edge case is vulnerable to changing the value on the user side (it is a hidden field after all and not a setting in the code). Considering that it has been used in only an extreme edge case for the past several PHP versions and frameworks don't use it anymore it might be a good idea to remove it or better yet refactor it in the core code to something that works. Because with current PHP versions the only check that is done is the upload_max_filesize ini directive on the php side. And, preferably, also a manual check inside the code on the server side comparing a manual configuration value to a file size of the uploaded file. Previous Comments: ------------------------------------------------------------------------ [2016-06-24 18:45:58] cmb@php.net Indeed, this is quite certainly not a doc bug, see <https://github.com/php/php-src/blob/php-7.0.8/main/rfc1867.c#L1049-L1053>. ------------------------------------------------------------------------ [2015-09-15 21:38:18] requinix@php.net As far as I can tell the intention of MAX_FILE_SIZE was to abort the upload, so the fact that files continue to be uploaded (which I've confirmed happens with PHP 5.5 + Apache 2.4 + mod_php) seems to be a bug. Perhaps rather than getting rid of something deemed useless, it can be fixed to work as expected. ------------------------------------------------------------------------ [2015-09-15 11:57:02] olafvdspek at gmail dot com The value isn't ignored, but it's checked AFTER the entire file was uploaded. ------------------------------------------------------------------------ [2015-09-15 11:54:14] requinix@php.net The sentence before that is > The MAX_FILE_SIZE hidden field (measured in bytes) must precede the file input > field, and its value is the maximum filesize accepted by PHP. If you have a repro script that has this field appearing before the file input and the value is still ignored, please share it so the problem can be fixed. ------------------------------------------------------------------------ [2015-09-15 11:06:53] olafvdspek at gmail dot com Description: ------------ > This form element should always be used as it saves users the trouble of waiting for a big file > being transferred only to find that it was too large and the transfer failed. As far as I know this bit is incorrect. It does NOT avoid a too-large file from being uploaded as the value is only checked AFTER the file was uploaded completely. http://php.net/manual/en/features.file-upload.post-method.php IMO MAX_FILE_SIZE is useless and should be dropped entirely. Test script: --------------- - ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70501&edit=1

« previous php.bugs (#218132) next »