fix(upload): sanitize multipart filename for folder uploads (#121)

Browsers send the full relative path (e.g. 'Screenshots/file.png') as
the multipart filename when uploading folders via webkitRelativePath.
The File entity rejects names containing '/' or '\', causing all files
in a folder upload to fail with 'Invalid file name'.

Three fixes:
- Backend: strip path components from multipart filename in file_handler,
  keeping only the basename. Also prevents path-traversal attacks.
- Frontend (fileOperations.js): explicitly pass file.name as the third
  argument to FormData.append() in uploadFolderFiles() to override the
  browser's relative path.
- Frontend (ui.js): detect folder drops in drag-and-drop handlers by
  checking webkitRelativePath, and route them to uploadFolderFiles()
  instead of uploadFiles() so subfolders are created first.

Closes #121
This commit is contained in:
Dionisio
2026-02-16 17:58:50 +01:00
parent f70890e884
commit a4709426d9
4 changed files with 35 additions and 5 deletions
+3 -1
View File
@@ -279,7 +279,9 @@ const fileOps = {
const formData = new FormData();
formData.append('folder_id', targetFolderId);
formData.append('file', file);
// Use file.name as the explicit filename to prevent the browser
// from sending the full webkitRelativePath as the filename
formData.append('file', file, file.name);
const displayName = file.webkitRelativePath || file.name;