Problem/Motivation

Upgrade to 6.3.1(security update), a Webform with a file upload field loses file on submit for anonymous and shows error "The uploaded file is invalid"

Steps to reproduce

  1. Use a webform with a managed_file element
  2. Upload a file, submit webform
  3. You'll get "The uploaded file is invalid" — the file is cleared

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

Comments

priyankampatil created an issue. See original summary.

priyankampatil’s picture

Issue summary: View changes
liam morland’s picture

priyankampatil’s picture

No, this is a completely different scenario. In our case, an anonymous user is unable to submit a webform containing a managed file field and receives “The uploaded file is invalid” error, whereas an authenticated user can successfully submit the same form with the same file field. This issue is not related to resuming a draft or re-uploading a previously uploaded file.

liam morland’s picture

Is this new between 6.3.0 and 6.3.1? Can you use git bisect to figure out which commit caused the problem?

cilefen’s picture

Status: Active » Postponed (maintainer needs more info)
Issue tags: +Possible duplicate
priyankampatil’s picture

Similar issue of file getting removed on webform submit caused by webform update from 6.3.0 to 6.3.1. #3619282: Upgrade to 11.4.5, a Webform with a file upload field loses file on submit for anonymous issue got resolved by reverting #3593472: Insecure Direct Object Reference in Private File Uploads code.