Problem/Motivation

Since 6.3.1, WebformManagedFileBase::valueCallback() rejects files already uploaded in the form when $file->access('download') returns FALSE.

The File Entity module (2.2.0) replaces core's file access handler with FileEntityAccessControlHandler. Unlike core's handler, it has no rule allowing anonymous users to access their own temporary private uploads (fid stored in the session's 'anonymous_allowed_file_ids').

As a result, for anonymous users, any file already in the form is rejected on the next request: uploading a second file or submitting the form displays "The uploaded file is invalid." and clears the first file. Forms with several managed file elements become unusable.

Tested with Webform 6.3.1, File Entity 2.2.0, Drupal 10.5.2 and 10.6.18. Webform 6.2.9 was not affected.

While debugging we confirmed: the file is temporary, owned by uid 0 (the current user), the fid_token is present and valid, the fid is in 'anonymous_allowed_file_ids', and webform_file_access() returns neutral. Only FileEntityAccessControlHandler denies download access.

Steps to reproduce

1. Install Drupal 10 with Webform 6.3.1 and File Entity 2.2.0.
2. Create a webform with two managed file elements using the private file scheme, open to anonymous users.
3. As an anonymous user, upload a file in the first element, then a file in the second element.
4. "The uploaded file is invalid." is displayed and the first file is removed.

Proposed resolution

This check only accepts temporary files, so instead of relying on $file->access('download'), apply core's rules for temporary files explicitly: the file must be temporary and owned by the current user, and for anonymous users (non-public scheme) its fid must be in the session's 'anonymous_allowed_file_ids', in addition to the existing HMAC token check.

Tampering protection is unchanged: a fid from another session is still rejected (tested manually).

Alternatively, this could be considered a File Entity issue, since its access handler lacks core's rule for anonymous temporary files.

Remaining tasks

Review the attached patch.
Add test coverage with File Entity enabled, if relevant.

User interface changes

None.

API changes

None.

Data model changes

None.

Issue fork webform-3626842

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

alexmcc5552 created an issue. See original summary.

ramartinez’s picture

I had the same issue, and can confirm that installing this patch resolves the issue for me.

yepa made their first commit to this issue’s fork.

yepa’s picture

Hi Folks,
Same bug encountered on Drupal 10.6, file entity 2.6.0 and webform 6.3.1.
Patch works fine.
I added a commit to read through the session service, as core's file access handler does because \Drupal::request()->getSession() throws a LogicException when the request carries no session.
Best.