fix(upload): sanitize multipart filename for folder uploads (#121)
Browsers send the full relative path (e.g. 'Screenshots/file.png') as the multipart filename when uploading folders via webkitRelativePath. The File entity rejects names containing '/' or '\', causing all files in a folder upload to fail with 'Invalid file name'. Three fixes: - Backend: strip path components from multipart filename in file_handler, keeping only the basename. Also prevents path-traversal attacks. - Frontend (fileOperations.js): explicitly pass file.name as the third argument to FormData.append() in uploadFolderFiles() to override the browser's relative path. - Frontend (ui.js): detect folder drops in drag-and-drop handlers by checking webkitRelativePath, and route them to uploadFolderFiles() instead of uploadFiles() so subfolders are created first. Closes #121
This commit is contained in:
@@ -279,7 +279,9 @@ const fileOps = {
|
||||
|
||||
const formData = new FormData();
|
||||
formData.append('folder_id', targetFolderId);
|
||||
formData.append('file', file);
|
||||
// Use file.name as the explicit filename to prevent the browser
|
||||
// from sending the full webkitRelativePath as the filename
|
||||
formData.append('file', file, file.name);
|
||||
|
||||
const displayName = file.webkitRelativePath || file.name;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user