jamesfredley commented on issue #9462:
URL: https://github.com/apache/grails-core/issues/9462#issuecomment-5945383800
Fixed on `8.0.x`.
`<g:uploadForm method="PUT">` submits `multipart/form-data` as POST with
`_method=PUT`. `request.getFile('attachment')` then failed because
`HiddenHttpMethodFilter` wrapped the request in `HttpMethodRequestWrapper`
before the multipart body was parsed, and that wrapper has no `getFile` method.
As of Grails 8 that filter is not registered unless
`grails.web.hiddenmethod.filter.enabled` or
`spring.mvc.hiddenmethod.filter.enabled` is set
(`GrailsHiddenHttpMethodFilterAutoConfiguration`).
`GrailsDispatcherServlet.checkMultipart` parses the multipart body first,
publishes it for `request.getFile`, and then records the `_method` override.
`request.method` stays POST. `allowedMethods` sees PUT through
`HiddenHttpMethod.effectiveMethod`.
`FileUploadSpec."method override still applies to a multipart upload"` posts
multipart plus `_method=PUT` to an action limited to PUT, calls
`request.getFile('file')`, and expects HTTP 200 and the uploaded filename. That
test was added in bb2a8b0492 (2026-08-17). The filter-off-by-default behavior
is in b7b744f9e4 (2026-08-30). Both commits are in `v8.0.0-RC1` and
`v8.0.0-RC2` only. Grails 7.2.4 still registers `HiddenHttpMethodFilter` on the
chain. Closing because the reported form works on `8.0.x`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]