Site banner change bug
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
Research direction
Start with src/Filament/Pages/Settings/ManageTheme.php and inspect the banner upload validation around preventFilePathTampering(). Reproduce the existing-banner case in Manage Theme with FILESYSTEM_DISK=local, then verify that the current banner appears, can be removed, and can be replaced without the file-path error.
Written by the indexing model from the issue text.
Description
Hi!
After installing Cachet I navigated to "Manage Theme" in Dasboard to upload a custom banner image.
I accidentally uploaded a wrong image and was about to replace it just to get an error "The banner image field contains a file path that is not permitted."
I tried multiple different images but then I noticed that the site shows the image but the "Manage Theme" page did not. I couldn't even remove the uploaded image. Without making any changes but hitting the save button gave also "The banner image field contains a file path that is not permitted."
After a lot of investigating I figured out the reason. The Filament is rejecting the stored path during validation.
I tried to run "artisan optimize:clear". My .env has "FILESYSTEM_DISK=local" setting.
I had to make an change to:
vendor/cachethq/core/src/Filament/Pages/Settings/ManageTheme.php
I changed:
->preventFilePathTampering()
to
->preventFilePathTampering( allowFilePathUsing: fn (string $file): bool => \Illuminate\Support\Facades\Storage::disk( (string) config('cachet.uploads.disk') )->exists($file) )
After this the "Manage Theme" started showing the current banner image. I was able to delete that and upload a new image
- Dominant language
- PHP
- Stars
- 230
- Forks
- 83
- Avg merge
- 1d 2m
- Merged PRs (30d)
- 7
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from cachethq/core
-
Banner image upload fails with "The banner image field contains a file path that is not permitted"Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
filament
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Similar issues
-
[CoreBundle] Migrations are silently skipped on MariaDB with DBAL 4 (AbstractMigration::isMySql())OpenPotential Bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Sylius/Sylius#19270 · 1 comment · 4 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
invoiceninja/invoiceninja#13320 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Перевод устарел
Difficulty 2/5 1-3 hours Newbie friendliness 68/100