how to handle errors thrown in Request::capture() in index.php?

Viewed 446
  • Laravel Version: 8 (last version)
  • PHP Version: 7.4.10
  • Database Driver & Version: MySql 5.6

Description:

Exceptions that are thrown in index.php in Request::capture() is not handled by the error handler \App\Exceptions\Handler.php.

In my case: there is an antivirus in the server which deletes any infected uploaded file. When the user uploads an infected file. what happens is:

  1. the user uploads file.
  2. PHP puts the file path in the global request.
  3. the antivirus deletes the file.
  4. Symfony tries to construct the file here SymfonyRequest::createFromGlobals()
  5. Symfony checks the file here vendor/symfony/http-foundation/File/File.php:
public function __construct(string $path, bool $checkPath = true)
{
  if ($checkPath && !is_file($path)) {
    throw new FileNotFoundException($path);
  }

  parent::__construct($path);
}

  1. exception is thrown and it's going to show it in the browser (security issue) Fatal error: Uncaught Symfony\Component\HttpFoundation\File\Exception\FileNotFoundException: The file "/tmp/php6CKu5H" does not exist in /home/vagrant/code/eskan/vendor/symfony/http-foundation/File/File.php on line 35

Steps To Reproduce:

  1. Set up fresh Laravel installment.
  2. throw the error in vendor/symfony/http-foundation/File/File.php like this:
public function __construct(string $path, bool $checkPath = true)
{
  throw new FileNotFoundException($path);
  if ($checkPath && !is_file($path)) {
  }

  parent::__construct($path);
}

Note: any thrown error in Request::capture() can have the same case. my issue link in laravel repo

0 Answers
Related