In-Portal Issue Tracker

Welcome to the In-Portal Open Source CMS Issue Tracker! This is a central management / tracking tool for all types of tasks / issues / bugs for the In-Portal Project. Before reporting any issues, please make sure to read the Guide into Issue Tracker and How to Properly Test and Report Bugs!

Viewing Issue Advanced Details Jump to Notes ] Wiki ] View Simple ] Issue History ] Print ]
ID Category Type Reproducibility Date Submitted Last Update
0000662 [In-Portal CMS] Data Management bug report always 2010-03-27 17:28 2010-07-22 15:03
Reporter BaSSiST View Status public Project Name In-Portal CMS
Assigned To alex Developer
Priority normal Resolution fixed Platform
Status closed   OS
  OS Version
ETA none Fixed in Version 5.1.0-B2 Product Version 5.0.3-B1
  Target Version 5.1.0 Product Build
Time EstimateNo estimate
Summary 0000662: Filenames of uploaded files are not escaped, when used in url
Description Try to upload file with symbols such as "#" or "+" in file name via
our standard SWF uploader. You'll see that when full url is built,
it's incorrect because file name is not urlencoded. Also this is
applicable to folder names in URL - for example, in URL
http://www.sitename.com/system/part1/part2/filename.ext part1, part2 &
filename.ext (& system?) need to be urlencoded. Another case is non-
formatter URL building to uploaded files, I found one in OnViewFile
event.
Steps To Reproduce
Additional Information
Tags No tags attached.
Reference http://groups.google.com/group/in-portal-bugs/browse_thread/thread/20695723e4de34bd
Change Log Message
Estimate Points 0
Attached Files patch file icon escaping_filenames_in_url.patch [^] (9,692 bytes) 2010-06-01 04:14 [Show Content]

- Relationships Relation Graph ] Dependency Graph ]
related to 0000456closed (5.1.0)alex Major Flash Uploader Redesign 

-  Notes
User avatar (0002353)
Dmitry (manager)
2010-05-31 22:30

Reminder sent to: alex

I propose to move this to 5.1.0 along with other Flash Uploader tasks.

Please complete task and commit into 5.1.0.

User avatar (0002364)
alex (manager)
2010-06-01 04:15

Dmitry allowed me to commit this without testing. Testing will be performed as part if 5.1.0-B2 testing.
User avatar (0002365)
alex (manager)
2010-06-01 04:15

Fix committed to 5.1.x branch. Commit Message:

Fixes 0000662: Filenames of uploaded files are not escaped, when used in url
User avatar (0002366)
alex (manager)
2010-06-01 04:22

Reminder sent to: Dmitry

Please test. You can use "Копия horseback_ridding1 ! ' (aa) # to be.JPG" filename for tests, since it contains all (at least I think so) problematic symbols and non-latin chars too.
User avatar (0002509)
alex (manager)
2010-07-22 15:03

Closing, since 5.1.0 release has been released.

- Related Changesets
In-Portal CMS: 5.1.x r13667
Timestamp: 2010-06-01 04:15:35
Author: alex
Details ] Diff ]
Fixes 0000662: Filenames of uploaded files are not escaped, when used in url
mod - /in-portal/branches/5.1.x/core/admin_templates/js/script.js Diff ] File ]
mod - /in-portal/branches/5.1.x/core/admin_templates/js/uploader/upload_manager.js Diff ] File ]
mod - /in-portal/branches/5.1.x/core/admin_templates/js/uploader/uploader.js Diff ] File ]
mod - /in-portal/branches/5.1.x/core/kernel/db/db_event_handler.php Diff ] File ]
mod - /in-portal/branches/5.1.x/core/kernel/utility/formatters/upload_formatter.php Diff ] File ]
mod - /in-portal/branches/5.1.x/core/units/helpers/file_helper.php Diff ] File ]
mod - /in-portal/branches/5.1.x/core/units/helpers/image_helper.php Diff ] File ]

- Issue History
Date Modified Username Field Change
2010-07-22 15:03 alex Note Added: 0002509
2010-07-22 15:03 alex Status resolved => closed
2010-07-11 08:47 alex Issue End Monitor: alex
2010-06-01 04:22 alex Issue Monitored: Dmitry
2010-06-01 04:22 alex Note Added: 0002366
2010-06-01 04:15 alex Note Added: 0002365
2010-06-01 04:15 alex Status reviewed and tested => resolved
2010-06-01 04:15 alex Fixed in Version => 5.1.0-B2
2010-06-01 04:15 alex Resolution open => fixed
2010-06-01 04:15 alex Assigned To !COMMUNITY => alex
2010-06-01 04:15 alex Changeset attached 5.1.x r13667
2010-06-01 04:15 alex Note Added: 0002364
2010-06-01 04:15 alex Status needs testing => reviewed and tested
2010-06-01 04:14 alex Assigned To => !COMMUNITY
2010-06-01 04:14 alex Developer => alex
2010-06-01 04:14 alex Status active => needs testing
2010-06-01 04:14 alex File Added: escaping_filenames_in_url.patch
2010-06-01 01:41 alex Target Version Icebox => 5.1.0
2010-05-31 22:30 Dmitry Issue Monitored: alex
2010-05-31 22:30 Dmitry Note Added: 0002353
2010-05-30 09:46 alex Relationship added related to 0000456
2010-05-10 14:50 alex Target Version 5.0.4 => Icebox
2010-03-27 17:29 alex Reporter alex => BaSSiST
2010-03-27 17:28 alex New Issue
2010-03-27 17:28 alex Reference => http://groups.google.com/group/in-portal-bugs/browse_thread/thread/20695723e4de34bd



Web Development by Intechnic
In-Portal Open Source CMS
In-Portal Open Source CMS
Copyright © 2000 - 2009 MantisBT Group

Powered by Mantis Bugtracker