October: Richeditor uploading files and images is not working

Created on 17 Apr 2019  路  13Comments  路  Source: octobercms/october

  • OctoberCMS Build: build 447 and up to latest
  • PHP Version: 7.2

Description:

CMS uses the froala editor froala which can upload a file or image. When trying to upload an image or file it throws back an error. Saying that something wen't wrong. This happends because the CSRF token is not being passsed through the AJAX request.

Temporay fix: diable CSRF token security....

Steps To Reproduce:

  1. Clone and install OctoberCMS from Github.
  2. create a simple plugin which uses a riche editor.
  3. Upload a file or image through the froala editor.
  4. receive error :)
High Completed Bug

All 13 comments

I also noticed this bug and can confirm that the error is caused by the CSRF token not being passed. Uploading images using the media tab, or the browse button -> upload is working fine. Just uploading images within the button popup isn't working. Issue can be reproduced in safari and chrome browser. Using PHP 7.2 and build 451

Just going to put a side note here, October is using Froala Editor V2.4.2 and current Version is 2.9.5. Though I think is not easy to update as there are many custom bug fixes with October and Froala. I leave the admins to decide.

@ayumihamsaki2 Froala was updated to 2.9.3 in Build 449.

Sorry my bad I was looking at the master branch and not the dev branch.

@LukeTowers Is it possible that this bug can be marked as Priority: high? This bug will cause many plugins to fail with the rich-editor formwidget. User will not be able to upload files or images in the rich-editor. I'm also trying to fix this bug.

@cheb60 As a workaround, users can upload images if they hit the browse button and upload a new image in the popup window. It's far from perfect so a bug fix is needed asap.

@bennothommo can you take a look at this?

@LukeTowers will do.

PR here: #4302

@cheb60 @webstylecenter @ayumihamsaki could you please test #4302?

@LukeTowers @bennothommo Thank you. I just checked the PR. When I upload an image it says invalid security token in the response (403). You can see the image in the richeditor but after that it dissapears. It does not work yet.

@cheb60 Would you be able to confirm that the "_token" key was sent in the post data when uploading a file or image directly in Froala?

This should be fixed in 3e5449c8550c6ea7d0d17062c46506c1078f8954

Was this page helpful?
0 / 5 - 0 ratings

Related issues

m49n picture m49n  路  3Comments

jvanremoortere picture jvanremoortere  路  3Comments

lukaszbanas-extremecoding picture lukaszbanas-extremecoding  路  3Comments

Flynsarmy picture Flynsarmy  路  3Comments

SeekAndPwn picture SeekAndPwn  路  3Comments