Skip to content

hash '#' or question-mark '?' is not accepted in filenames #28748

Description

@individual-it

Steps to reproduce

  1. try to rename a file into something containing a hash # or a question-mark ?

Expected behaviour

file renamed correctly

Actual behaviour

  1. if a filename didn't contain a problematic char #/? before the rename and the resulting filename is different to the source filename when you strip away anything after the #/? (e.g. rename file => file2#123): the UI shows the correct new filename but after a reload you see that the problematic char #/? got striped away silently from the name
  2. if a filename didn't contain a problematic char #/?`` before the rename and the resulting filename is same as source filename when you strip away anything after the #/?(e.g. renamefile=>file#123): an error is displayed The name "file#123" is already used in the folder "/". Please choose a different name.`
  3. if the filename did already contain a problematic char #/? before the rename and the new name only changes characters after the problematic char #/? (eg. rename file# to file#.txt: an error is displayed Could not rename "file#"
  4. if the filename did already contain a problematic char #/? before the rename and the new name only changes characters before the hash # (eg. rename file# to file2#: the UI shows the correct new filename but after a reload you see that the problematic char #/? got striped away silently from the name. This is why UI tests fail with
    image

Issue started from #28732

Server configuration

Operating system:
Debian
Web server:
Apache
Database:
SQlite
PHP version:
7.1.6
ownCloud version: (see ownCloud admin page)
git master
Updated from an older ownCloud or fresh install:
fresh
Where did you install ownCloud from:
git

Client configuration

Browser:
FF 55, Chrome 60
Operating system:
Debian

ownCloud log (data/owncloud.log)

for case 1 in "Actual behaviour": none
for case 2 in "Actual behaviour":

{"reqId":"WL5v0sjCQwuB1WhFilWG","level":0,"time":"2017-08-21T06:00:31+00:00","remoteAddr":"::1","user":"admin","app":"webdav","method":"MOVE","url":"\/owncloud-core\/remote.php\/dav\/files\/admin\/file","message":"Exception: {\"Message\":\"HTTP\\\/1.1 412 The destination node already exists, and the overwrite header is set to false\",\"Exception\":\"Sabre\\\\DAV\\\\Exception\\\\PreconditionFailed\",\"Code\":0,\"Trace\":\"#0 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/CorePlugin.php(624): Sabre\\\\DAV\\\\Server->getCopyAndMoveInfo(Object(Sabre\\\\HTTP\\\\Request))\\n#1 [internal function]: Sabre\\\\DAV\\\\CorePlugin->httpMove(Object(Sabre\\\\HTTP\\\\Request), Object(Sabre\\\\HTTP\\\\Response))\\n#2 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/event\\\/lib\\\/EventEmitterTrait.php(105): call_user_func_array(Array, Array)\\n#3 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php(479): Sabre\\\\Event\\\\EventEmitter->emit('method:MOVE', Array)\\n#4 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php(254): Sabre\\\\DAV\\\\Server->invokeMethod(Object(Sabre\\\\HTTP\\\\Request), Object(Sabre\\\\HTTP\\\\Response))\\n#5 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/apps\\\/dav\\\/lib\\\/Server.php(234): Sabre\\\\DAV\\\\Server->exec()\\n#6 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/apps\\\/dav\\\/appinfo\\\/v2\\\/remote.php(31): OCA\\\\DAV\\\\Server->exec()\\n#7 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/remote.php(175): require_once('\\\/home\\\/artur\\\/www...')\\n#8 {main}\",\"File\":\"\\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php\",\"Line\":758,\"User\":\"admin\"}"}

for case 3 in "Actual behaviour":

{"reqId":"o9WwvkJiKoDyipzS55ck","level":0,"time":"2017-08-21T06:01:25+00:00","remoteAddr":"::1","user":"admin","app":"webdav","method":"MOVE","url":"\/owncloud-core\/remote.php\/dav\/files\/admin\/file","message":"Exception: {\"Message\":\"HTTP\\\/1.1 412 The destination node already exists, and the overwrite header is set to false\",\"Exception\":\"Sabre\\\\DAV\\\\Exception\\\\PreconditionFailed\",\"Code\":0,\"Trace\":\"#0 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/CorePlugin.php(624): Sabre\\\\DAV\\\\Server->getCopyAndMoveInfo(Object(Sabre\\\\HTTP\\\\Request))\\n#1 [internal function]: Sabre\\\\DAV\\\\CorePlugin->httpMove(Object(Sabre\\\\HTTP\\\\Request), Object(Sabre\\\\HTTP\\\\Response))\\n#2 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/event\\\/lib\\\/EventEmitterTrait.php(105): call_user_func_array(Array, Array)\\n#3 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php(479): Sabre\\\\Event\\\\EventEmitter->emit('method:MOVE', Array)\\n#4 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php(254): Sabre\\\\DAV\\\\Server->invokeMethod(Object(Sabre\\\\HTTP\\\\Request), Object(Sabre\\\\HTTP\\\\Response))\\n#5 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/apps\\\/dav\\\/lib\\\/Server.php(234): Sabre\\\\DAV\\\\Server->exec()\\n#6 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/apps\\\/dav\\\/appinfo\\\/v2\\\/remote.php(31): OCA\\\\DAV\\\\Server->exec()\\n#7 \\\/home\\\/artur\\\/www\\\/owncloud-core\\\/remote.php(175): require_once('\\\/home\\\/artur\\\/www...')\\n#8 {main}\",\"File\":\"\\\/home\\\/artur\\\/www\\\/owncloud-core\\\/lib\\\/composer\\\/sabre\\\/dav\\\/lib\\\/DAV\\\/Server.php\",\"Line\":758,\"User\":\"admin\"}"}

for case 4 in "Actual behaviour": none

Browser log

for case 1 in "Actual behaviour":
image
for case 2 in "Actual behaviour":
image
for case 3 in "Actual behaviour":


image
for case 4 in "Actual behaviour":
image

Activity

  1. changed the title [-]has '#' is not accepted in filenames when renaming[/-] [+] hash '#' or question-mark '?' is not accepted in filenames[/+] on Aug 21, 2017
  2. individual-it commented on Aug 21, 2017

    @individual-it
    MemberAuthor

    more problems when:

    1. creating a folder containing a #/' or ?
    2. deleting a file/folder with a #/' or ? in the name
      there is even a potential for destroying data:
      1. having 2 files called file and file#
      2. delete file# => no error, but file was deleted file# is still intact
  3. added this to the development milestone on Aug 21, 2017
  4. self-assigned this
    on Aug 21, 2017
  5. phil-davis commented on Aug 21, 2017

    @phil-davis
    Contributor

    I guess there need to be tests for renaming, deleting etc anything with special characters in the name that might be confused as delimiters in a URI.

  6. PVince81 commented on Aug 21, 2017

    @PVince81
    Contributor

    Only happening on master, not stable10. I think I know what it is... fixing

  7. PVince81 commented on Aug 21, 2017

    @PVince81
    Contributor

    Pfff this sucks...

    Basically on master I switched to using encodeURI instead of encodeURIComponent for path sections. Apparently encodeURI doesn't encode hashes and question marks.

    I could switch it back, which might be fine.

    However the fix for usernames with "@" character on new dav was the same: I switched to "encodeURI". This means that now usernames with "#" in them won't work either on master...

    I'll see if I can find a middle ground, sadly this seems to imply writing our own custom encoding method... or additionally manually encode at signs.

  8. PVince81 commented on Aug 21, 2017

    @PVince81
    Contributor

    Fix is here #28749.

    I used a different approach: now we still encode with encodeURIComponent like we did before the previous fix. But considering that Sabre DAV doesn't encode "@" signs, we now compare the root path from the href response section by section in their decoded form. (we need to do this to extract the sub-path from the href in the PROPFIND response)

  9. lock commented on Aug 1, 2019

    @lock

    This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

  10. locked as resolved and limited conversation to collaborators on Aug 1, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions