Bug->Req #77372 [Opn]: Relative file path is removed from uploaded file
| From: | requinix@php.net | Date: | Wed, 02 Jan 2019 18:09:22 +0000 |
| Subject: | Bug->Req #77372 [Opn]: Relative file path is removed from uploaded file | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218755@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77372&edit=1
ID: 77372
Updated by: requinix@php.net
Reported by: nospam at unclassified dot de
Summary: Relative file path is removed from uploaded file
Status: Open
-Type: Bug
+Type: Feature/Change Request
Package: *Directory/Filesystem functions
Operating System: Windows 10
PHP Version: 7.0.33
Block user comment: N
Private report: N
New Comment:
There's no way PHP could know whether it should keep or remove any directory portion of the
original filename, and there is far too much code out there that trusts the name to be a basename.
The only method I see for this is to introduce another array entry for the whole path - the value
submitted by the client, unchanged. Like "original_name" or something. That should be a
relatively minor change for PHP and it shouldn't impact any existing code.
Browser support is a bit contradictory:
https://caniuse.com/#search=webkitdirectory
https://developer.mozilla.org/en-US/docs/Web/API/HTMLInputElement/webkitdirectory#Browser_compatibility
Previous Comments:
------------------------------------------------------------------------
[2019-01-02 17:39:04] cmb@php.net
Hmm, the webkitdirectory attribute[1] is part of the âFile and
Directory Entries APIâ which is a very recent *draft*, so I
wouldn't assess non-compliance with this feature a bug in PHP per
se.
Anyhow, the relevant code[2] that causes this behavior is due to a
quirk of IE, namely that even recent versions of IE 11 allow to
âInclude local directory path when uploading files to a serverâ.
However, while the code originally just catered to backslashes
(like the comment still indicates), it has been replaced with a
more general _basename()[3] which also caters to (forward)
slashes. So, at the very least, the comment is wrong.
[1] <https://wicg.github.io/entries-api/#dom-htmlinputelement-webkitdirectory>
[2] <https://github.com/php/php-src/blob/php-7.3.0/main/rfc1867.c#L1149-L1154>
[3] <http://github.com/php/php-src/commit/cdb9ee0d1a5ecb843b320c9effb81207f4280795>
------------------------------------------------------------------------
[2018-12-29 22:49:28] nospam at unclassified dot de
Description:
------------
<input type="file" name="files" multiple webkitdirectory>
This allows the user to select a directory and have all its files uploaded, also from all
subdirectories. In Firefox, the POST request correctly contains the relative paths of all uploaded
files. In PHP, the paths are removed and only the file names are available.
$_FILES['files']['name'][...]:
Actual value: 'file.png'
Expected value: 'sub/dir/file.png'
This makes the entire directory uploading feature unusable because the structure gets lost and file
names may even become duplicate and useless.
Note, I have searches for "upload webkitdirectory" but only got tons of unrelated results,
so I might have missed a real duplicate. Please improve your search if you want to avoid duplicates.
Test script:
---------------
See above.
Expected result:
----------------
See above.
Actual result:
--------------
See above.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77372&edit=1