Bug #79045 [Com]: Incorrect svg mimetypes detected

From: Date: Mon, 30 Dec 2019 02:03:51 +0000
Subject: Bug #79045 [Com]: Incorrect svg mimetypes detected
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224607@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79045&edit=1

 ID:                 79045
 Comment by:         phpbugs-xap2kka at mpan dot pl
 Reported by:        sloth at 0k dot vc
 Summary:            Incorrect svg mimetypes detected
 Status:             Open
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Centos 7.5
 PHP Version:        7.2.26
 Block user comment: N
 Private report:     N

 New Comment:

“With PHP 7.4.1 *it* returns the same, *but* file 5.37 (on Arch) offers a different
output” of course. Too many bugs. :)


Previous Comments:
------------------------------------------------------------------------
[2019-12-30 02:01:36] phpbugs-xap2kka at mpan dot pl

With PHP 7.4.1 returns the same, bug file 5.37 (on Arch) offers a different output:

Test.svg:  image/svg+xml; charset=utf-8
badge.svg: image/svg; charset=us-ascii

That doesn’t explain, however, why is PHP 7.2.26 returning a different value and why
“image/svg” is returned instead of “image/svg+xml”. I do understand that
badge.svg is not an XML file and one may be tempted to remove that “+xml”, but if it is
not an XML, it is also not an SVG and “image/svg” is equally incorrect. Plus it is not the
registered type for SVG.

------------------------------------------------------------------------
[2019-12-30 01:41:49] sloth at 0k dot vc

More descriptive title

------------------------------------------------------------------------
[2019-12-30 01:30:14] sloth at 0k dot vc

Description:
------------
PHP when given an svg perhaps without the xml header, will return a mime type of image/svg instead
of image/svg+xml, however IANA does not list image/svg as an existant mimetype, nor do browsers
display it. (https://www.iana.org/assignments/media-types/media-types.xhtml)

By SVG standards, mimetype returned should always be image/svg+xml, php should also behave
consistently for a single type of file. If this is being used to differentiate properly headered
SVGs from those that are not as strict, this should be done as part of a file validity check not a
mime type check.

Previously reported bug (https://bugs.php.net/bug.php?id=76543) was indicated as "Not a
bug" due to it being deemed as upstream fault with libmagic. However, libmagic returns svgs
missing the xml header as text/plain. This indicates the fault is in the adaptations PHP took to
remove that error.

└(~) $ file -i Test.svg
Test.svg: image/svg+xml; charset=utf-8
└(~) $ file -i badge.svg
badge.svg: text/plain; charset=us-ascii

As only php is returning image/svg and this is not a registered mimetype, this can be considered a
bug with php.

Test images:
Working svg+xml: https://upload.wikimedia.org/wikipedia/commons/b/bd/Test.svg
SVG returned as image/svg: https://img.shields.io/badge/License-WTFPL-brightgreen.svg

Test script:
---------------
<?php
echo mime_content_type('./badge.svg'), "\n";
echo mime_content_type('./Test.svg'), "\n";

$finfo = new finfo(FILEINFO_MIME);

$buffer = file_get_contents('./badge.svg');
echo $finfo->buffer($buffer) . "\n";
$buffer = file_get_contents('./Test.svg');
echo $finfo->buffer($buffer) . "\n";


Expected result:
----------------
image/svg+xml
image/svg+xml
image/svg+xml; charset=us-ascii
image/svg+xml; charset=utf-8


Actual result:
--------------
image/svg
image/svg+xml
image/svg; charset=us-ascii
image/svg+xml; charset=utf-8



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79045&edit=1


Thread (12 messages)

« previous php.bugs (#224607) next »