?
avatar compojoom
compojoom
24 May 2016

As far as I understand there is a new security feature that scans the content of a zip file uploaded through the media manager and forbids the upload if that zip file contains any php files.

In my case this is pretty stupid as I want people to upload zip files containing php code, but anyway. That's not the point of this issue here.

When uploading such an "incorrect" file I would expect to at least get an error message or at a warning. Instead the page just refreshes and no message is displayed.

Steps to reproduce the issue

Go to media manager. (make sure that you have set the zip file extension in the allowed extension types) Try to upload a zip file containing php files.

Expected result

The file should upload.

Actual result

The file doesn't upload and not error message is shown. The file list just refreshes.

System information (as much as possible)

Tested on several 3.5.1 installations

Additional comments

I tried to upload the test zip files here but GitHub says "unfortunately, we don't support that file type", which is also pretty confusing as ZIP is listed as a supported file type, but it's way better than joomla's omission of an error whatsoever.

avatar compojoom compojoom - open - 24 May 2016
avatar brianteeman brianteeman - change - 24 May 2016
Labels Added: ?
avatar zero-24 zero-24 - change - 24 May 2016
Category Media Manager
avatar zero-24
zero-24 - comment - 24 May 2016

Can you provide the file e.g. via GD or Dropbox or similiar?


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10609.

avatar conconnl
conconnl - comment - 2 Jul 2016

The new MediaManager improvements project can be found here, maybe it's good to fix it in the new version.
https://github.com/joomla-projects/media-manager-improvement


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10609.

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 6 Apr 2017

@conconnl have you opened an issue so i can close this Issue?


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/10609.

avatar joomla-cms-bot joomla-cms-bot - change - 6 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 6 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 6 Apr 2017
Status New Information Required
avatar conconnl
conconnl - comment - 6 Apr 2017

No and i'm not sure for what I need to make a issue. I don't have any issues at the moment.

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 6 Apr 2017

@conconnl i misread your comment above, sorry for that.

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 6 Apr 2017
avatar laoneo
laoneo - comment - 6 Apr 2017

Yes I think it is a good idea, then we have it tracked.

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 6 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 6 Apr 2017
The description was changed
Status Information Required Closed
Closed_Date 0000-00-00 00:00:00 2017-04-06 15:48:39
Closed_By franz-wohlkoenig
avatar joomla-cms-bot joomla-cms-bot - change - 6 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 6 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 6 Apr 2017
Closed_Date 2017-04-06 15:48:39 2017-04-06 15:48:40
Closed_By franz-wohlkoenig joomla-cms-bot
avatar joomla-cms-bot joomla-cms-bot - close - 6 Apr 2017
avatar joomla-cms-bot
joomla-cms-bot - comment - 6 Apr 2017

Add a Comment

Login with GitHub to post a comment