I'm getting a really weird issue. Using User 1 I can upload without a problem. Any other user, including a secondary Admin user with ALL permissions gets the following error:

"The file -----.--- could not be uploaded, only files with the following extensions are allowed: ."

No file extensions are actually shown only a period "." I'm using the same file for testing.

I've tried mod-security. Didn't work.

Comments

eugenmayer’s picture

Priority: Critical » Normal
Status: Active » Postponed (maintainer needs more info)

Cannot confirm this.

Dont forget to give the user user permission "upload with swfupload" (group settings) and doublecheck admin/settings/uploads so you have no malformed filefilter. I tried both, having none entered ( no restriction ) and having some files in there like "jpg gif png odf". You see, no dots before the extensions

FranCarstens’s picture

Yup, that's exactly how I have it. I have permissions for SWFupload as well as upload to authenticated, admin and another role. I also have jpg psd pdf as allowed extensions. When trying to upload only those are allowed and everything works fine until it's started uploading and then I get the error message. Again, uploads work for UID 1, but for no other users - with either authenticated, admin or other role. I'm seeing no error messages except the one in the screen shot. Server logs show nothing, neither does Drupal log.

eugenmayer’s picture

Use the SWFUpload debug mode (debug:true in the settings) and look at the trace

FranCarstens’s picture

This is the trace I get. I don't see anything new (I've removed pieces of the upload progress since it's just a repitition.):

---SWFUpload Instance Info---
Version: 2.2.0 2009-03-25
Movie Name: SWFUpload_0
Settings:
upload_url: /swfupload
flash_url: /sites/all/libraries/swfupload/swfupload.swf?preventswfcaching=1274732348717
use_query_string: false
requeue_on_error: false
http_success:
assume_success_timeout: 0
file_post_name: field_album_files
post_params: [object Object]
file_types: *.pdf;*.jpeg;*.jpg;*.ai;*.indd;*.zip
file_types_description:

Upload your albums pages here. Please note the following:

  • Be sure to number pages consecutively for ex. Name_Page01.pdf, Name_Page02.pdf, etc.
  • The following formats are allowed: PDF, Jpeg, Adobe™ Illustrator, Adobe™ Indesign or any of these files types compressed as ZIP.
  • We suggest uploading a compressed ZIP file to save time selecting files.

file_size_limit: 0
file_upload_limit: 0
file_queue_limit: 0
debug: true
prevent_swf_caching: true
button_placeholder_id: field_album_files-swfwrapper
button_placeholder: Not Set
button_image_url: /node/add/
button_width: 104
button_height: 28
button_text:
button_text_style: color: #000000; font-size: 16pt;
button_text_top_padding: 0
button_text_left_padding: 0
button_action: -110
button_disabled: false
custom_settings: [object Object]
Event Handlers:
swfupload_loaded_handler assigned: true
file_dialog_start_handler assigned: false
file_queued_handler assigned: true
file_queue_error_handler assigned: true
upload_start_handler assigned: false
upload_progress_handler assigned: true
upload_error_handler assigned: true
upload_success_handler assigned: true
upload_complete_handler assigned: true
debug_handler assigned: true

SWF DEBUG: SWFUpload Init Complete
SWF DEBUG:
SWF DEBUG: ----- SWF DEBUG OUTPUT ----
SWF DEBUG: Build Number: SWFUPLOAD 2.2.0
SWF DEBUG: movieName: SWFUpload_0
SWF DEBUG: Upload URL: /swfupload
SWF DEBUG: File Types String: *.pdf;*.jpeg;*.jpg;*.ai;*.indd;*.zip
SWF DEBUG: Parsed File Types: pdf,jpeg,jpg,ai,indd,zip
SWF DEBUG: HTTP Success: 0
SWF DEBUG: File Types Description:

Upload your albums pages here. Please note the following:

SWF DEBUG:

    SWF DEBUG:
  • Be sure to number pages consecutively for ex. Name_Page01.pdf, Name_Page02.pdf, etc.
  • SWF DEBUG:

  • The following formats are allowed: PDF, Jpeg, Adobe™ Illustrator, Adobe™ Indesign or any of these files types compressed as ZIP.
  • SWF DEBUG:

  • We suggest uploading a compressed ZIP file to save time selecting files.
  • SWF DEBUG:

(*.pdf;*.jpeg;*.jpg;*.ai;*.indd;*.zip)
SWF DEBUG: File Size Limit: 0 bytes
SWF DEBUG: File Upload Limit: 0
SWF DEBUG: File Queue Limit: 0
SWF DEBUG: Post Params:
SWF DEBUG: op=move_uploaded_file
SWF DEBUG: instance={ "name": "field_album_files" }
SWF DEBUG: widget={ "file_extensions": "pdf jpeg jpg ai indd zip", "file_path": "albums_uploads", "progress_indicator": "bar", "max_filesize_per_file": "", "max_filesize_per_node": "", "max_resolution": "0", "min_resolution": "0", "alt": "", "custom_alt": 0, "title": "", "custom_title": 0, "title_type": "textfield", "default_image": null, "use_default_image": 0, "label": "Album Files", "weight": "-3", "description": "\x3cp\x3eUpload your albums pages here. Please note the following:\x3c/p\x3e\r\n\x3cul\x3e\r\n\x3cli\x3eBe sure to number pages consecutively for ex. Name_Page01.pdf, Name_Page02.pdf, etc.\x3c/li\x3e\r\n\x3cli\x3eThe following formats are allowed: PDF, Jpeg, Adobe™ Illustrator, Adobe™ Indesign or any of these files types compressed as ZIP.\x3c/li\x3e\r\n\x3cli\x3eWe suggest uploading a compressed ZIP file to save time selecting files.\x3c/li\x3e\r\n\x3c/ul\x3e", "type": "swfupload_widget", "module": "swfupload", "list_field": "0", "list_default": 1, "description_field": "0" }
SWF DEBUG: sid=3433302a6465613336313636636538333134633463623162363565613939623766396262
SWF DEBUG: file_path=sites/default/files/albums_uploads
SWF DEBUG: ----- END SWF DEBUG OUTPUT ----
SWF DEBUG:
SWF DEBUG: Event: fileDialogStart : Browsing files. Multi Select. Allowed file types: *.pdf;*.jpeg;*.jpg;*.ai;*.indd;*.zip
SWF DEBUG: Select Handler: Received the files selected from the dialog. Processing the file list...
SWF DEBUG: Event: fileQueued : File ID: SWFUpload_0_0
SWF DEBUG: Event: fileDialogComplete : Finished processing selected files. Files selected: 1. Files Queued: 1
SWF DEBUG: StartUpload: First file in queue
SWF DEBUG: Event: uploadStart : File ID: SWFUpload_0_0
SWF DEBUG: Global Post Item: op=move_uploaded_file
SWF DEBUG: Global Post Item: instance={ "name": "field_album_files" }
SWF DEBUG: Global Post Item: widget={ "file_extensions": "pdf jpeg jpg ai indd zip", "file_path": "albums_uploads", "progress_indicator": "bar", "max_filesize_per_file": "", "max_filesize_per_node": "", "max_resolution": "0", "min_resolution": "0", "alt": "", "custom_alt": 0, "title": "", "custom_title": 0, "title_type": "textfield", "default_image": null, "use_default_image": 0, "label": "Album Files", "weight": "-3", "description": "\x3cp\x3eUpload your albums pages here. Please note the following:\x3c/p\x3e\r\n\x3cul\x3e\r\n\x3cli\x3eBe sure to number pages consecutively for ex. Name_Page01.pdf, Name_Page02.pdf, etc.\x3c/li\x3e\r\n\x3cli\x3eThe following formats are allowed: PDF, Jpeg, Adobe™ Illustrator, Adobe™ Indesign or any of these files types compressed as ZIP.\x3c/li\x3e\r\n\x3cli\x3eWe suggest uploading a compressed ZIP file to save time selecting files.\x3c/li\x3e\r\n\x3c/ul\x3e", "type": "swfupload_widget", "module": "swfupload", "list_field": "0", "list_default": 1, "description_field": "0" }
SWF DEBUG: Global Post Item: sid=3433302a6465613336313636636538333134633463623162363565613939623766396262
SWF DEBUG: Global Post Item: file_path=sites/default/files/albums_uploads
SWF DEBUG: ReturnUploadStart(): File accepted by startUpload event and readied for upload. Starting upload to /swfupload for File ID: SWFUpload_0_0
SWF DEBUG: Event: uploadProgress (OPEN): File ID: SWFUpload_0_0
SWF DEBUG: Event: uploadProgress: File ID: SWFUpload_0_0. Bytes: 129024. Total: 1100693
.....etc
SWF DEBUG: Event: uploadProgress: File ID: SWFUpload_0_0. Bytes: 1100693. Total: 1100693
SWF DEBUG: Event: uploadSuccess: File ID: SWFUpload_0_0 Response Received: true Data: { "op": "upload_complete", "file": 0, "file_path": "sites/default/files/albums_uploads", "instance": { "name": "field_album_files" }, "widget": null, "messages": { "error": [ "The selected file \x3cem\x3eLogo.ai\x3c/em\x3e could not be uploaded. Only files with the following extensions are allowed: \x3cem\x3e\x3c/em\x3e." ], "swfupload_error": [ "There was an error uploading the file" ] } }
SWF DEBUG: Event: uploadComplete : Upload cycle complete.
SWF DEBUG: StartUpload: First file in queue
SWF DEBUG: StartUpload(): No files found in the queue.

eugenmayer’s picture

well i guess its all about

SWF DEBUG: Event: uploadSuccess: File ID: SWFUpload_0_0 Response Received: true Data: { "op": "upload_complete", "file": 0, "file_path": "sites/default/files/albums_uploads", "instance": { "name": "field_album_files" }, "widget": null, "messages": { "error": [ "The selected file \x3cem\x3eLogo.ai\x3c/em\x3e could not be uploaded. Only files with the following extensions are allowed: \x3cem\x3e\x3c/em\x3e." ], "swfupload_error": [ "There was an error uploading the file" ] } }

Well this needs some debugging. Are you able to set a watchdog / dsm at the point where the extensions are checked and see what value it has actually?

eugenmayer’s picture

Status: Postponed (maintainer needs more info) » Needs work

confirmed.

It seems like no filetypes are found when user != 1. Inverstigating

skilip’s picture

The allowed extensions array seems to be empty: 'Only files with the following extensions are allowed: '

eugenmayer’s picture

Status: Needs work » Needs review

The reason is the description field of the upload field. If you use HTML characters there, you will get a hex encoded string in json. json_decode cant handle this.

We need this

function swfupload_js() {
  $p = (object) $_POST;
  $op = $p->op;
  $file = json_decode($p->file);
  $instance = json_decode($p->instance);
  $widget = json_decode(_swfupload_decode_hex($p->widget));

plus

function _swfupload_decode_hex($string) {
  $pos = 0;
  while( ($pos = strpos( $string, '\x', $pos )) !== FALSE ) {
    $h = $string[$pos+2].$string[$pos+3];
    $string = str_replace( '\x'.$h,
                          chr( hexdec($h) ),
                          $string );
  }
  return $string;
}
skilip’s picture

StatusFileSize
new686 bytes
heine’s picture

Are you sure swfupload is faulty here? The drupal_to_js core implementation creates broken JSON #479368: D7: Create RFC compliant HTML safe JSON. Maybe swfupload just returns the garbage it received?

If you already rely on the json "extension", why not make a custom drupal_to_js implementation (as the D7 version http://api.drupal.org/api/function/drupal_json_encode/7) until core is fixed.

eugenmayer’s picture

Status: Needs review » Needs work

Sounds like the better approach here. I will just use the d7 one.

skilip’s picture

Status: Needs work » Needs review

@Heine: I've tried using json_encode instead of drupal_to_js as well. The error still occurs so I assume it is caused by Flash. (I think Steve agrees ;))

skilip’s picture

Version: 6.x-2.0-beta3 » 6.x-2.0-beta4
StatusFileSize
new2.67 KB

Note that this patch runs on BETA4!

eugenmayer’s picture

Status: Needs review » Reviewed & tested by the community

patch looks fine!

skilip’s picture

Status: Reviewed & tested by the community » Patch (to be ported)
skilip’s picture

Status: Patch (to be ported) » Needs review
StatusFileSize
new2.74 KB

@Heine mentioned the returned data should be also be escaped for json_encode()

skilip’s picture

Status: Needs review » Patch (to be ported)
StatusFileSize
new2.72 KB

Minor changes on the functions comment.

skilip’s picture

Status: Patch (to be ported) » Needs review

Oops, too fast.... sry

eugenmayer’s picture

Priority: Normal » Critical

Marking critical, is a must for the rc1

sansui’s picture

Subscribing. Seems like this module is getting pretty close to stable release :) Looking forward to switching over to this from fupload when a few more of these issues are cleaned up :D

eugenmayer’s picture

There arent much (any) issues left actually. Help beta testing beta5, it should work quiet well already. This way we can release rc1 early in the future.

eugenmayer’s picture

Status: Needs review » Patch (to be ported)

Applied in branch http://github.com/EugenMayer/swfupload/tree/797638 ( base was beta 5)

merged into dev

eugenmayer’s picture

Status: Patch (to be ported) » Fixed

fixed in bet6

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.