Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Site banner change bug

Open Beginner friendly
#471 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
laravel, php
Domain
backend

Research direction

Start with src/Filament/Pages/Settings/ManageTheme.php and inspect the banner upload validation around preventFilePathTampering(). Reproduce the existing-banner case in Manage Theme with FILESYSTEM_DISK=local, then verify that the current banner appears, can be removed, and can be replaced without the file-path error.

Written by the indexing model from the issue text.

Description

Hi!

After installing Cachet I navigated to "Manage Theme" in Dasboard to upload a custom banner image.
I accidentally uploaded a wrong image and was about to replace it just to get an error "The banner image field contains a file path that is not permitted."

I tried multiple different images but then I noticed that the site shows the image but the "Manage Theme" page did not. I couldn't even remove the uploaded image. Without making any changes but hitting the save button gave also "The banner image field contains a file path that is not permitted."

After a lot of investigating I figured out the reason. The Filament is rejecting the stored path during validation.
I tried to run "artisan optimize:clear". My .env has "FILESYSTEM_DISK=local" setting.

I had to make an change to:
vendor/cachethq/core/src/Filament/Pages/Settings/ManageTheme.php

I changed:
->preventFilePathTampering()
to
->preventFilePathTampering( allowFilePathUsing: fn (string $file): bool => \Illuminate\Support\Facades\Storage::disk( (string) config('cachet.uploads.disk') )->exists($file) )

After this the "Manage Theme" started showing the current banner image. I was able to delete that and upload a new image

Dominant language
PHP
Stars
230
Forks
83
Avg merge
1d 2m
Merged PRs (30d)
7

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from cachethq/core

All issues in cachethq/core

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.