Edit report at https://bugs.php.net/bug.php?id=79045&edit=1
ID: 79045
Updated by: cmb@php.net
Reported by: sloth at 0k dot vc
Summary: Incorrect svg mimetypes detected
Status: Open
Type: Bug
Package: Filesystem function related
Operating System: Centos 7.5
PHP Version: 7.2.26
Block user comment: N
Private report: N
New Comment:
The result depends on the version of the magic data; for vanilla
file:
as of file 5.38: image/svg+xml
as of file 5.29: image/svg
former versions: text/plain
Note that file 5.38 has been released only two weeks ago, and that
we certainly won't switch back to the pre file 5.29 behavior.
Also note that active support for PHP 7.2 has ended one month
ago[1], so any fix for this could only go into PHP 7.3.
[1] <https://www.php.net/supported-versions.php>
Previous Comments:
------------------------------------------------------------------------
[2019-12-30 02:03:51] phpbugs-xap2kka at mpan dot pl
âWith PHP 7.4.1 *it* returns the same, *but* file 5.37 (on Arch) offers a different
outputâ of course. Too many bugs. :)
------------------------------------------------------------------------
[2019-12-30 02:01:36] phpbugs-xap2kka at mpan dot pl
With PHP 7.4.1 returns the same, bug file 5.37 (on Arch) offers a different output:
Test.svg: image/svg+xml; charset=utf-8
badge.svg: image/svg; charset=us-ascii
That doesnât explain, however, why is PHP 7.2.26 returning a different value and why
âimage/svgâ is returned instead of âimage/svg+xmlâ. I do understand that
badge.svg is not an XML file and one may be tempted to remove that â+xmlâ, but if it is
not an XML, it is also not an SVG and âimage/svgâ is equally incorrect. Plus it is not the
registered type for SVG.
------------------------------------------------------------------------
[2019-12-30 01:41:49] sloth at 0k dot vc
More descriptive title
------------------------------------------------------------------------
[2019-12-30 01:30:14] sloth at 0k dot vc
Description:
------------
PHP when given an svg perhaps without the xml header, will return a mime type of image/svg instead
of image/svg+xml, however IANA does not list image/svg as an existant mimetype, nor do browsers
display it. (https://www.iana.org/assignments/media-types/media-types.xhtml)
By SVG standards, mimetype returned should always be image/svg+xml, php should also behave
consistently for a single type of file. If this is being used to differentiate properly headered
SVGs from those that are not as strict, this should be done as part of a file validity check not a
mime type check.
Previously reported bug (https://bugs.php.net/bug.php?id=76543) was indicated as "Not a
bug" due to it being deemed as upstream fault with libmagic. However, libmagic returns svgs
missing the xml header as text/plain. This indicates the fault is in the adaptations PHP took to
remove that error.
â(~) $ file -i Test.svg
Test.svg: image/svg+xml; charset=utf-8
â(~) $ file -i badge.svg
badge.svg: text/plain; charset=us-ascii
As only php is returning image/svg and this is not a registered mimetype, this can be considered a
bug with php.
Test images:
Working svg+xml: https://upload.wikimedia.org/wikipedia/commons/b/bd/Test.svg
SVG returned as image/svg: https://img.shields.io/badge/License-WTFPL-brightgreen.svg
Test script:
---------------
<?php
echo mime_content_type('./badge.svg'), "\n";
echo mime_content_type('./Test.svg'), "\n";
$finfo = new finfo(FILEINFO_MIME);
$buffer = file_get_contents('./badge.svg');
echo $finfo->buffer($buffer) . "\n";
$buffer = file_get_contents('./Test.svg');
echo $finfo->buffer($buffer) . "\n";
Expected result:
----------------
image/svg+xml
image/svg+xml
image/svg+xml; charset=us-ascii
image/svg+xml; charset=utf-8
Actual result:
--------------
image/svg
image/svg+xml
image/svg; charset=us-ascii
image/svg+xml; charset=utf-8
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79045&edit=1