Skip to content

Different behavior between FileProvider and ImageProvider #2487

@StevenRenaux

Description

@StevenRenaux

Environment

Sonata packages

show

$ composer show --latest 'sonata-project/*'
Direct dependencies required in composer.json:
sonata-project/admin-bundle              4.36.0 4.36.2 The missing Symfony Admin Generator
sonata-project/classification-bundle     4.9.1  4.9.1  Symfony SonataClassificationBundle
sonata-project/doctrine-orm-admin-bundle 4.18.0 4.18.0 Integrate Doctrine ORM into the SonataAdminBundle
sonata-project/media-bundle              4.16.0 4.16.0 Symfony SonataMediaBundle
sonata-project/user-bundle               5.14.0 5.15.0 Symfony SonataUserBundle

Transitive dependencies not required in composer.json:
sonata-project/block-bundle              5.1.2  5.2.0  Symfony SonataBlockBundle
sonata-project/doctrine-extensions       2.5.0  2.5.0  Doctrine2 behavioral extensions
sonata-project/exporter                  3.3.1  3.3.1  Lightweight Exporter library
sonata-project/form-extensions           2.4.1  2.5.0  Symfony form extensions
sonata-project/twig-extensions           2.5.0  2.5.0  Sonata twig extensions

Symfony packages

show

$ composer show --latest 'symfony/*'
Direct dependencies required in composer.json:
symfony/asset                      v6.4.13 v7.3.0  Manages URL generation and versioning of web assets such as CSS stylesheets, JavaScript files and image files
symfony/browser-kit                v6.4.13 v7.3.0  Simulates the behavior of a web browser, allowing you to make requests, click on links and submit forms programmatically
symfony/console                    v6.4.17 v7.3.0  Eases the creation of beautiful and testable command line interfaces
symfony/css-selector               v6.4.13 v7.3.0  Converts CSS selectors to XPath expressions
symfony/debug-bundle               v6.4.13 v7.3.0  Provides a tight integration of the Symfony VarDumper component and the ServerLogCommand from MonologBridge into the Symfony fu...
symfony/doctrine-messenger         v6.4.18 v7.3.0  Symfony Doctrine Messenger Bridge
symfony/dotenv                     v6.4.16 v7.3.0  Registers environment variables from a .env file
symfony/expression-language        v6.4.13 v7.3.0  Provides an engine that can compile and evaluate expressions
symfony/flex                       v2.4.7  v2.7.1  Composer plugin for Symfony
symfony/form                       v6.4.13 v7.3.0  Allows to easily create, process and reuse HTML forms
symfony/framework-bundle           v6.4.18 v7.3.0  Provides a tight integration between Symfony components and the Symfony full-stack framework
symfony/http-client                v6.4.18 v7.3.0  Provides powerful methods to fetch HTTP resources synchronously or asynchronously
symfony/intl                       v6.4.15 v7.3.0  Provides access to the localization data of the ICU library
symfony/mailer                     v6.4.18 v7.3.0  Helps sending emails
symfony/maker-bundle               v1.62.1 v1.63.0 Symfony Maker helps you create empty commands, controllers, form classes, tests and more so you can forget about writing boiler...
symfony/messenger                  v6.4.16 v7.3.0  Helps applications send and receive messages to/from other applications or via message queues
symfony/mime                       v6.4.18 v7.3.0  Allows manipulating MIME messages
symfony/monolog-bundle             v3.10.0 v3.10.0 Symfony MonologBundle
symfony/notifier                   v6.4.13 v7.3.0  Sends notifications via one or more channels (email, SMS, ...)
symfony/phpunit-bridge             v6.4.16 v7.3.0  Provides utilities for PHPUnit, especially user deprecation notices management
symfony/process                    v6.4.15 v7.3.0  Executes commands in sub-processes
symfony/property-access            v6.4.18 v7.3.0  Provides functions to read and write from/to an object or array using a simple string notation
symfony/property-info              v6.4.18 v7.3.0  Extracts information about PHP class' properties using metadata of popular sources
symfony/runtime                    v6.4.14 v7.3.0  Enables decoupling PHP applications from global state
symfony/security-bundle            v6.4.13 v7.3.0  Provides a tight integration of the Security component into the Symfony full-stack framework
symfony/serializer                 v6.4.18 v7.3.0  Handles serializing and deserializing data structures, including object graphs, into array structures or other formats like XML...
symfony/stimulus-bundle            v2.22.1 v2.25.2 Integration with your Symfony app & Stimulus!
symfony/stopwatch                  v6.4.13 v7.3.0  Provides a way to profile code
symfony/string                     v6.4.15 v7.3.0  Provides an object-oriented API to strings and deals with bytes, UTF-8 code points and grapheme clusters in a unified way
symfony/translation                v6.4.13 v7.3.0  Provides tools to internationalize your application
symfony/twig-bundle                v6.4.13 v7.3.0  Provides a tight integration of Twig into the Symfony full-stack framework
symfony/ux-live-component          v2.24.0 v2.25.2 Live components for Symfony
symfony/validator                  v6.4.18 v7.3.0  Provides tools to validate values
symfony/web-link                   v6.4.13 v7.3.0  Manages links between resources
symfony/web-profiler-bundle        v6.4.18 v7.3.0  Provides a development tool that gives detailed information about the execution of any request
symfony/webpack-encore-bundle      v2.2.0  v2.2.0  Integration of your Symfony app with Webpack Encore
symfony/yaml                       v6.4.18 v7.3.0  Loads and dumps YAML files

Transitive dependencies not required in composer.json:
symfony/cache                      v6.4.18 v7.3.0  Provides extended PSR-6, PSR-16 (and tags) implementations
symfony/cache-contracts            v3.5.1  v3.6.0  Generic abstractions related to caching
symfony/clock                      v6.4.13 v7.3.0  Decouples applications from the system clock
symfony/config                     v6.4.14 v7.3.0  Helps you find, load, combine, autofill and validate configuration values of any kind
symfony/dependency-injection       v6.4.16 v7.3.0  Allows you to standardize and centralize the way objects are constructed in your application
symfony/deprecation-contracts      v3.5.1  v3.6.0  A generic function and convention to trigger deprecation notices
symfony/doctrine-bridge            v6.4.18 v7.3.0  Provides integration for Doctrine with various Symfony components
symfony/dom-crawler                v6.4.18 v7.3.0  Eases DOM navigation for HTML and XML documents
symfony/error-handler              v6.4.18 v7.3.0  Provides tools to manage errors and ease debugging PHP code
symfony/event-dispatcher           v6.4.13 v7.3.0  Provides tools that allow your application components to communicate with each other by dispatching events and listening to them
symfony/event-dispatcher-contracts v3.5.1  v3.6.0  Generic abstractions related to dispatching event
symfony/filesystem                 v6.4.13 v7.3.0  Provides basic utilities for the filesystem
symfony/finder                     v6.4.17 v7.3.0  Finds files and directories via an intuitive fluent interface
symfony/http-client-contracts      v3.5.2  v3.6.0  Generic abstractions related to HTTP clients
symfony/http-foundation            v6.4.18 v7.3.0  Defines an object-oriented layer for the HTTP specification
symfony/http-kernel                v6.4.18 v7.3.0  Provides a structured process for converting a Request into a Response
symfony/monolog-bridge             v6.4.13 v7.3.0  Provides integration for Monolog with various Symfony components
symfony/options-resolver           v6.4.16 v7.3.0  Provides an improved replacement for the array_replace PHP function
symfony/password-hasher            v6.4.13 v7.3.0  Provides password hashing utilities
symfony/polyfill-intl-grapheme     v1.31.0 v1.32.0 Symfony polyfill for intl's grapheme_* functions
symfony/polyfill-intl-icu          v1.31.0 v1.32.0 Symfony polyfill for intl's ICU-related data and classes
symfony/polyfill-intl-idn          v1.31.0 v1.32.0 Symfony polyfill for intl's idn_to_ascii and idn_to_utf8 functions
symfony/polyfill-intl-normalizer   v1.31.0 v1.32.0 Symfony polyfill for intl's Normalizer class and related functions
symfony/polyfill-mbstring          v1.31.0 v1.32.0 Symfony polyfill for the Mbstring extension
symfony/polyfill-php83             v1.31.0 v1.32.0 Symfony polyfill backporting some PHP 8.3+ features to lower PHP versions
symfony/routing                    v6.4.18 v7.3.0  Maps an HTTP request to a set of configuration variables
symfony/security-acl               v3.3.4  v3.3.4  Symfony Security Component - ACL (Access Control List)
symfony/security-core              v6.4.18 v7.3.0  Symfony Security Component - Core Library
symfony/security-csrf              v6.4.13 v7.3.0  Symfony Security Component - CSRF Library
symfony/security-http              v6.4.18 v7.3.0  Symfony Security Component - HTTP Integration
symfony/service-contracts          v3.5.1  v3.6.0  Generic abstractions related to writing services
symfony/translation-contracts      v3.5.1  v3.6.0  Generic abstractions related to translation
symfony/twig-bridge                v6.4.17 v7.3.0  Provides integration for Twig with various Symfony components
symfony/ux-twig-component          v2.24.0 v2.25.2 Twig components for Symfony
symfony/var-dumper                 v6.4.18 v7.3.0  Provides mechanisms for walking through any arbitrary PHP variable
symfony/var-exporter               v6.4.13 v7.3.0  Allows exporting any serializable PHP data structure to plain PHP code
symfony/workflow                   v6.4.13 v7.3.0  Provides tools for managing a workflow or finite state machine

PHP version

$ php -v
PHP 8.2.28 

Subject

The behavior between image and file submission in a form is not the same when "allowed_extensions" or "allowed_mime_types" are not as expected.

Steps to reproduce

When I submit a file with an incorrect extension, I get this return related to my field

    private ?SonataMediaMedia $ficheDeFonctionnement = null;

Image

Image

When I submit the same form for an image file, I don't get the same response. Not link to the field anymore.

    private ?SonataMediaMedia $couverture = null;

Image

Image

Expected results

After digging into the code a bit, it seems to be because we threw an exception in the ImageProvider::doTransform() method.

About allowedExtensions

throw new UploadException(\sprintf(

About allowedMimeTypes

throw new UploadException(\sprintf(

If I understand correctly, doTransform method only transforms the data like a DataTransformer does in a Symfony form. It might not also be supposed to validate it.

Because if I comment out these "validation steps," the validation is performed by the parent method FileProvider::validate().
FileProvider::validate() validates the extension and MIME types, and adds the violation to the field (also ideal when translations are required).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions