Skip to content

Detect real file content for the mimes validation rule - #324

Merged
techmahedy merged 1 commit into
doppar:4.xfrom
techmahedy:techmahedy-4.x
Sep 18, 2026
Merged

techmahedy merged 1 commit into
doppar:4.xfrom
techmahedy:techmahedy-4.x

Conversation

@techmahedy

Copy link
Copy Markdown
Member

Why

ValidationRules::validateFile()'s mimes case only compared the client-supplied filename's extension against the allowed list:

$file['name'] is fully attacker-controlled — renaming shell.php to shell.pdf defeats this check entirely, so sanitize(['file' => 'mimes:pdf,doc']) would accept a PHP payload as long as it was named with an allowed extension.

What changed

mimes now detects the file's real content type via symfony/mime's MimeTypes::guessMimeType() (backed by the fileinfo extension) and checks it against the MIME types normally associated with each allowed extension.

@techmahedy techmahedy added the enhancement New feature or request label Sep 18, 2026
@techmahedy
techmahedy merged commit 85eb4ef into doppar:4.x Sep 18, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant