Skip to content

Allow saving a stored banner image in Manage Theme - #480

Open
VincentBorgers wants to merge 1 commit into
cachethq:mainfrom
VincentBorgers:allow-saving-stored-banner-image
Open

VincentBorgers wants to merge 1 commit into
cachethq:mainfrom
VincentBorgers:allow-saving-stored-banner-image

Conversation

@VincentBorgers

Copy link
Copy Markdown

Summary

  • Saving the Manage Theme settings page fails once a banner image is stored, with The banner image field contains a file path that is not permitted. This also blocks replacing or removing the banner (Banner image upload fails with "The banner image field contains a file path that is not permitted"聽#467, Site banner change bug聽#471).
  • The app_banner FileUpload uses preventFilePathTampering(). On a settings page the existing stored path is not registered as an allowed path, so the guard rejects it on every save, even when nothing changed.
  • Pass allowFilePathUsing to permit a path when the file actually exists on the configured uploads disk. Tampered or non-existent paths are still rejected; a stored banner is accepted again. The closure uses the same disk the field already uploads to.
  • Add a regression test that saves the page with a banner already stored.

Validation

  • The new test fails on main with the error above and passes with the fix.
  • vendor/bin/pest: 1145 passed (4237 assertions), after composer build.
  • vendor/bin/pint --test: passed.
  • vendor/bin/phpstan analyse src/Filament/Pages/Settings/ManageTheme.php: no errors.

Fixes #467
Fixes #471

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Site banner change bug Banner image upload fails with "The banner image field contains a file path that is not permitted"

1 participant