Req #77372 [Com]: Relative file path is removed from uploaded file

From: Date: Thu, 06 Jan 2022 07:42:18 +0000
Subject: Req #77372 [Com]: Relative file path is removed from uploaded file
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238789@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77372&edit=1 ID: 77372 Comment by: Poortmansimon at defensie dot world Reported by: nospam at unclassified dot de Summary: Relative file path is removed from uploaded file Status: Closed Type: Feature/Change Request Package: *Directory/Filesystem functions Operating System: Windows 10 PHP Version: 7.0.33 Block user comment: N Private report: N New Comment: HER MAJESTY SIMON POORTMAN STATE V. GENERAL BONDKANSELIER. HIS MAJESTY THE KING OF THE BELGIANS, THE PRESIDENT OF THE FEDERAL REPUBLIC OF GERMANY, THE PRESIDENT OF THE FRENCH REPUBLIC, THE PRESIDENT OF THE ITALIAN REPUBLIC, HIS ROYAL HIGHNESS THE GRAND DUKE OF LUXEMBOURG, HIS MAJESTY THE KING OF THE NETHERLANDS. KING OFF THE EUROPEAN REPUBLIC COMMUNITY. KING OF THE WORLD. Name : Simon Poortman Job: Generaal V. Bondchancellor Adres: Ministerlaan 44 8014PK Zwolle Netherlands E-mail: Poortmansimon@defensie.world Telephone: +31610325665 Bank account: IBAN: NL40RABO 0119769794 BIC: RABONL2U Adres: Ministerlaan 44 8014PK Zwolle Netherlands Previous Comments: ------------------------------------------------------------------------ [2021-05-14 09:43:57] git@php.net Automatic comment on behalf of bjoern-tantau (author) and web-flow (committer) Revision: https://github.com/php/php-src/commit/d764f1dc12a1778d0c82c474430cb1da16038473 Log: Fix #77372: Retain full path of files for directory uploads (#6917) ------------------------------------------------------------------------ [2021-04-26 16:19:15] bugs dot php dot net at s dot bjoern-tantau dot de You could use #74611 as a workaround and parse the upload yourself, using php://input. ------------------------------------------------------------------------ [2019-01-03 11:32:38] nospam at unclassified dot de I wouldn't call the browser support contradictory. Every current desktop browser supports this feature for a few versions already. 95% of all desktop users should be able to use it today. IE is not current and about to die. The concept of uploading large amounts of files probably doesn't fit into mobile devices anyway so I don't consider it a problem when these platforms don't support it. The thing is, the HTTP request does contain that information about the provided path. PHP just drops it. And when the PHP manual contains code examples that suggest applying basename on the file name, I was assuming that it isn't basename'd already and browsers may or may not send a path there and I must remove it when I don't need it (or my code isn't prepared to validate it). I might need to go down and parse the HTTP request myself in PHP to extract the required information. ------------------------------------------------------------------------ [2019-01-02 18:09:22] requinix@php.net There's no way PHP could know whether it should keep or remove any directory portion of the original filename, and there is far too much code out there that trusts the name to be a basename. The only method I see for this is to introduce another array entry for the whole path - the value submitted by the client, unchanged. Like "original_name" or something. That should be a relatively minor change for PHP and it shouldn't impact any existing code. Browser support is a bit contradictory: https://caniuse.com/#search=webkitdirectory https://developer.mozilla.org/en-US/docs/Web/API/HTMLInputElement/webkitdirectory#Browser_compatibility ------------------------------------------------------------------------ [2019-01-02 17:39:04] cmb@php.net Hmm, the webkitdirectory attribute[1] is part of the “File and Directory Entries API” which is a very recent *draft*, so I wouldn't assess non-compliance with this feature a bug in PHP per se. Anyhow, the relevant code[2] that causes this behavior is due to a quirk of IE, namely that even recent versions of IE 11 allow to “Include local directory path when uploading files to a server”. However, while the code originally just catered to backslashes (like the comment still indicates), it has been replaced with a more general _basename()[3] which also caters to (forward) slashes. So, at the very least, the comment is wrong. [1] <https://wicg.github.io/entries-api/#dom-htmlinputelement-webkitdirectory> [2] <https://github.com/php/php-src/blob/php-7.3.0/main/rfc1867.c#L1149-L1154> [3] <http://github.com/php/php-src/commit/cdb9ee0d1a5ecb843b320c9effb81207f4280795> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77372 -- Edit this bug report at https://bugs.php.net/bug.php?id=77372&edit=1

« previous php.bugs (#238789) next »