Doc #70501 [Opn]: MAX_FILE_SIZE does not abort upload

From: Date: Fri, 24 Jun 2016 18:45:58 +0000
Subject: Doc #70501 [Opn]: MAX_FILE_SIZE does not abort upload
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-13598@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70501&edit=1 ID: 70501 Updated by: cmb@php.net Reported by: olafvdspek at gmail dot com -Summary: MAX_FILE_SIZE docs incorrect +Summary: MAX_FILE_SIZE does not abort upload Status: Open Type: Documentation Problem -Package: Documentation problem +Package: *Web Server problem Operating System: * PHP Version: 5.6.13 Block user comment: N Private report: N New Comment: Indeed, this is quite certainly not a doc bug, see <https://github.com/php/php-src/blob/php-7.0.8/main/rfc1867.c#L1049-L1053>. Previous Comments: ------------------------------------------------------------------------ [2015-09-15 21:38:18] requinix@php.net As far as I can tell the intention of MAX_FILE_SIZE was to abort the upload, so the fact that files continue to be uploaded (which I've confirmed happens with PHP 5.5 + Apache 2.4 + mod_php) seems to be a bug. Perhaps rather than getting rid of something deemed useless, it can be fixed to work as expected. ------------------------------------------------------------------------ [2015-09-15 11:57:02] olafvdspek at gmail dot com The value isn't ignored, but it's checked AFTER the entire file was uploaded. ------------------------------------------------------------------------ [2015-09-15 11:54:14] requinix@php.net The sentence before that is > The MAX_FILE_SIZE hidden field (measured in bytes) must precede the file input > field, and its value is the maximum filesize accepted by PHP. If you have a repro script that has this field appearing before the file input and the value is still ignored, please share it so the problem can be fixed. ------------------------------------------------------------------------ [2015-09-15 11:06:53] olafvdspek at gmail dot com Description: ------------ > This form element should always be used as it saves users the trouble of waiting for a big file > being transferred only to find that it was too large and the transfer failed. As far as I know this bit is incorrect. It does NOT avoid a too-large file from being uploaded as the value is only checked AFTER the file was uploaded completely. http://php.net/manual/en/features.file-upload.post-method.php IMO MAX_FILE_SIZE is useless and should be dropped entirely. Test script: --------------- - ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70501&edit=1

« previous php.doc.bugs (#13598) next »