This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 1b2ad67e5ff4cf9ea181ef7cd749dd7681554312 Author: opencode <[email protected]> AuthorDate: Wed Sep 30 11:12:02 2026 +0200 Fall back to the raw trimmed filename value in ApplicationPart.getSubmittedFileName() when HttpParser.unquote() rejects an invalid quoted-string, keeping the result consistent with the file-vs-field classification performed by FileUploadBase.getFileName() for malformed Content-Disposition headers --- java/org/apache/catalina/core/ApplicationPart.java | 7 +++- .../apache/catalina/core/TestApplicationPart.java | 44 ++++++++++++++++++++++ 2 files changed, 50 insertions(+), 1 deletion(-) diff --git a/java/org/apache/catalina/core/ApplicationPart.java b/java/org/apache/catalina/core/ApplicationPart.java index 95a7167b19..db523e22cd 100644 --- a/java/org/apache/catalina/core/ApplicationPart.java +++ b/java/org/apache/catalina/core/ApplicationPart.java @@ -161,7 +161,12 @@ public class ApplicationPart implements Part { // RFC 6266. This is either a token or a quoted-string if (fileName.indexOf('\\') > -1) { // This is a quoted-string - fileName = HttpParser.unquote(fileName.trim()); + String unquoted = HttpParser.unquote(fileName.trim()); + // If the quoted-string was invalid (e.g. ended + // with a backslash) fall back to the raw value to + // remain consistent with the classifier used by + // the multipart parser (FileUploadBase.getFileName) + fileName = unquoted != null ? unquoted : fileName.trim(); } else { // This is a token fileName = fileName.trim(); diff --git a/test/org/apache/catalina/core/TestApplicationPart.java b/test/org/apache/catalina/core/TestApplicationPart.java new file mode 100644 index 0000000000..6b278a1216 --- /dev/null +++ b/test/org/apache/catalina/core/TestApplicationPart.java @@ -0,0 +1,44 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with + * this work for additional information regarding copyright ownership. + * The ASF licenses this file to You under the Apache License, Version 2.0 + * (the "License"); you may not use this file except in compliance with + * the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.apache.catalina.core; + +import org.junit.Assert; +import org.junit.Test; + +import org.apache.tomcat.util.http.fileupload.disk.DiskFileItem; +import org.apache.tomcat.util.http.fileupload.util.FileItemHeadersImpl; + +public class TestApplicationPart { + + private static ApplicationPart createPart(String contentDisposition) { + DiskFileItem fileItem = new DiskFileItem("field", "text/plain", false, "name", 102400, null); + FileItemHeadersImpl headers = new FileItemHeadersImpl(); + headers.addHeader("Content-Disposition", contentDisposition); + fileItem.setHeaders(headers); + return new ApplicationPart(fileItem, null); + } + + + @Test + public void testSubmittedFileNameUnterminatedQuotedString() { + // An escaped closing quote makes the quoted-string invalid. + // getSubmittedFileName() must not diverge (return null) from the + // classifier used by the multipart parser (which yields "abc\"). + ApplicationPart part = createPart("form-data; name=\"x\"; filename=\"abc\\\""); + Assert.assertEquals("abc\\", part.getSubmittedFileName()); + } +} --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
