Repository navigation
Default fileExtension regex does not match plain files. #8698
Description
Activity
parse-github-assistant commented
on Jul 23, 2023 More actionsThanks for opening this issue!
- ❌ Please fill out all fields with a placeholder
FILL_THIS_OUT, otherwise your issue will be closed. If a field does not apply to the issue, fill inn/a.
- ❌ Please fill out all fields with a placeholder
Related: parse-community/Parse-SDK-JS#1979
I think the default regex should instead be
'^(?!html$|htm$).*'- addedtype:bugImpaired feature or lacking behavior that is likely assumedImpaired feature or lacking behavior that is likely assumed
on Jul 23, 2023 From the web server point of view, the path component of a URI is case sensitive, so we cannot add the
iflag to the regex. On the other hand modern web browsers handle file extensions case-insensitive (file.HTML,file.html,file.HtMl, etc. are all rendered as HTML).So to truly prevent HTML content files we'd need to block any case-style without using the
iflag, that's why we had the regex so far.If we don't keep the current case insensitive regex style, then the regex could be simply
^(?!html?$). This requires only 4 steps for the regex engine, regardless of the extension string length. But that would allow uploadingmalicious.HTmLand browsers would likely render the HTML content.If we want to keep the case insensitive style then we could use
^(?!(h|H)(t|T)(m|M)(l|L)?$), which should- not match
html,htmwith any casing combination (e.g.html,HTMLHtMl) - match empty string
'', i.e. no file extension - match any other extension
Btw, the current file extension regex looks wrong anyway as it won't allow extensions shorter than 3 or longer than 4 chars.
- not match
Is it possible that a file could be uploaded with the extension
hTmL?If the file extension regex is
["^(?!html?$)"]without theiflag, then yes, and a browser would render it. But we can't use theiflag, because we would limit developers who differentiate casing in the URI, technicallyindex.HTMLandindex.htmlcould be 2 different files. So we'd need^(?!(h|H)(t|T)(m|M)(l|L)?$).🎉 This change has been released in version 7.0.0-alpha.26
- addedstate:released-alphaReleased as alpha versionReleased as alpha version
on Mar 10, 2024 🎉 This change has been released in version 7.0.0-beta.1
- addedstate:released-betaReleased as beta versionReleased as beta version
on Mar 19, 2024 🎉 This change has been released in version 7.0.0
- addedstate:releasedReleased as stable versionReleased as stable version
on Mar 19, 2024
New Issue Checklist
Issue Description
The current default
fileExtensionregex ("^[^hH][^tT][^mM][^lL]?$") does not matchplain.Steps to reproduce
Actual Outcome
Error
Expected Outcome
Should succeed
Environment
Server
FILL_THIS_OUTFILL_THIS_OUTFILL_THIS_OUTDatabase
FILL_THIS_OUTFILL_THIS_OUTFILL_THIS_OUTClient
FILL_THIS_OUTFILL_THIS_OUTLogs