Problem/Motivation

The 'allow all extensions' behaviour has some quirks:

Filename Allowed extension Allow insecure uploads? Action Valid?
foo.txt 'txt' FALSE Valid extension ✅ Valid
foo.txt Not set FALSE Use default extensions ✅ Valid
foo.txt Empty string '' FALSE Not a valid extension ❌ Invalid

Steps to reproduce

Proposed resolution

Provide an explicit flag to allow all extensions on the \Drupal\file\Plugin\Validation\Constraint\FileExtensionConstraint so the FileExtensionConstraintValidator can just skip if a flag is set.

Remaining tasks

User interface changes

API changes

Data model changes

Release notes snippet

Issue fork drupal-3403253

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

kim.pepper created an issue. See original summary.

kim.pepper’s picture

Issue summary: View changes
kim.pepper’s picture

Issue summary: View changes
alexpott’s picture

I don't think we should simplify it at all. I think we need to make it harder. Ideally only with the contrib module "Bad judgement" installed. At the very least we should prevent it from working in core unless the setting allow_insecure_uploads is set to true. Because if you set it to any empty string you are allowing insecure uploads... yes by default nothing from the \Drupal\Core\File\FileSystemInterface::INSECURE_EXTENSIONS list but still everything else... like I'm pretty sure I could exploit being able to upload an htm file and having inline JS. If I can trick a logged in user to visit that URL... profit.

Version: 11.x-dev » main

Drupal core is now using the main branch as the primary development branch. New developments and disruptive changes should now be targeted to the main branch.

Read more in the announcement.