Active
Project:
Drupal core
Version:
main
Component:
file.module
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
22 Nov 2023 at 00:52 UTC
Updated:
1 May 2024 at 08:57 UTC
Jump to comment: Most recent
The 'allow all extensions' behaviour has some quirks:
| Filename | Allowed extension | Allow insecure uploads? | Action | Valid? |
|---|---|---|---|---|
| foo.txt | 'txt' |
FALSE | Valid extension | ✅ Valid |
| foo.txt | Not set | FALSE | Use default extensions | ✅ Valid |
| foo.txt | Empty string '' |
FALSE | Not a valid extension | ❌ Invalid |
Provide an explicit flag to allow all extensions on the \Drupal\file\Plugin\Validation\Constraint\FileExtensionConstraint so the FileExtensionConstraintValidator can just skip if a flag is set.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
kim.pepperComment #4
kim.pepperComment #5
alexpottI don't think we should simplify it at all. I think we need to make it harder. Ideally only with the contrib module "Bad judgement" installed. At the very least we should prevent it from working in core unless the setting allow_insecure_uploads is set to true. Because if you set it to any empty string you are allowing insecure uploads... yes by default nothing from the \Drupal\Core\File\FileSystemInterface::INSECURE_EXTENSIONS list but still everything else... like I'm pretty sure I could exploit being able to upload an htm file and having inline JS. If I can trick a logged in user to visit that URL... profit.