The submission download form uses the short date format to generate a placeholder date within the date range fields. The validation function for the form passes the user input through strtotime() to generate a dates that can be validated.

However, it is possible to set the short date format to be a date format that is invalid for use in strtotime(): for example "dd/mm/yyyy" will be interpreted by strtotime() as an American "mm/dd/yyyy" format. In such cases, it is possible for a user to enter a date as directed by the placeholder text and for it to then fail validation: the date 30/05/2017 would be interpreted by strtotime() as the invalid 5th day of the 30th month, 2017.

The query generator for date ranges also uses strtotime(), and so suffers the same limitation, although the validation bug prevents this from being apparent.

Comments

MrDaleSmith created an issue. See original summary.

mrdalesmith’s picture

Status: Active » Needs review
StatusFileSize
new3.26 KB

Attached is a patch to change the validation and query builder to use DateTime objects, which can be generated using the same Drupal date filter that generated the placeholder within the field. In this way, the validation will only fail if the date format entered does not match that suggested to the inputter.

liam morland’s picture

Status: Needs review » Needs work

Thanks for the patch. A re-roll is needed.

mrdalesmith’s picture

Status: Needs work » Needs review
StatusFileSize
new2.85 KB

Rerolled patch.

liam morland’s picture

Status: Needs review » Fixed

Thanks!

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

farooq.salmani’s picture

@Liam Morland: When is it going to release please?

liam morland’s picture

I will probably make a release candidate in 10 days. In the meantime, you can use the development snapshot.