Skip to content

Harden Files input method against executable file uploads - #51

Open
cyrez wants to merge 3 commits into
joomla-framework:3.x-devfrom
cyrez:patch-1
Open

cyrez wants to merge 3 commits into
joomla-framework:3.x-devfrom
cyrez:patch-1

Conversation

@cyrez

@cyrez cyrez commented Jun 22, 2026 •

Copy link
Copy Markdown

Pull Request in relation with PR https://github.com/joomla-framework/filesystem/pull/81/changes

Summary of Changes

This PR returns the "old" hardening behavior of the CMS Input Files get method

Testing Instructions

Code review, compare with original code of the CMS package (libraries/src/Input/Files.php > libraries/vendor/joomla/input/src/Files.php)

cyrez added 2 commits June 22, 2026 15:48
Removed the filter parameter from the get method and updated the return information.
Added a filter parameter to the get method to allow filtering of input values.
@cyrez cyrez changed the title Refactor get method by removing filter parameter Harden Files input method against executable file uploads Jun 22, 2026
@cyrez

cyrez commented Aug 25, 2026

Copy link
Copy Markdown
Author

Update PR with correct namespace for isSafeFile (i was using CMS instead of framework namespace).

Replaced Joomla/Filter/InputFilter by Joomla/Filesystem/File

@heelc29

heelc29 commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

The filesystem package is not available

input/composer.json

Lines 8 to 19 in b4ef792

"require": {
"php": "^8.1.0",
"joomla/filter": "^3.0",
"symfony/deprecation-contracts": "^2|^3"
},
"require-dev": {
"joomla/test": "^3.0",
"phpunit/phpunit": "^9.5.28",
"squizlabs/php_codesniffer": "^3.7.2",
"phpstan/phpstan": "1.12.27",
"phpstan/phpstan-deprecation-rules": "1.2.1"
},

@cyrez

cyrez commented Aug 28, 2026 •

Copy link
Copy Markdown
Author

The filesystem package is not available

input/composer.json

Lines 8 to 19 in b4ef792

"require": {
"php": "^8.1.0",
"joomla/filter": "^3.0",
"symfony/deprecation-contracts": "^2|^3"
},
"require-dev": {
"joomla/test": "^3.0",
"phpunit/phpunit": "^9.5.28",
"squizlabs/php_codesniffer": "^3.7.2",
"phpstan/phpstan": "1.12.27",
"phpstan/phpstan-deprecation-rules": "1.2.1"
},

Oh yes, you're right!

So, i will wait for a maintainer to check if better to include Filesystem or to add isSafeFile to the inputFilter.
I think @Hackwar you are the person i'm looking for? :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants