- Laravel Version: 8 (last version)
- PHP Version: 7.4.10
- Database Driver & Version: MySql 5.6
Description:
Exceptions that are thrown in index.php in Request::capture() is not handled by the error handler \App\Exceptions\Handler.php.
In my case: there is an antivirus in the server which deletes any infected uploaded file. When the user uploads an infected file. what happens is:
- the user uploads file.
- PHP puts the file path in the global request.
- the antivirus deletes the file.
- Symfony tries to construct the file here
SymfonyRequest::createFromGlobals() - Symfony checks the file here
vendor/symfony/http-foundation/File/File.php:
public function __construct(string $path, bool $checkPath = true)
{
if ($checkPath && !is_file($path)) {
throw new FileNotFoundException($path);
}
parent::__construct($path);
}
- exception is thrown and it's going to show it in the browser (security issue)
Fatal error: Uncaught Symfony\Component\HttpFoundation\File\Exception\FileNotFoundException: The file "/tmp/php6CKu5H" does not exist in /home/vagrant/code/eskan/vendor/symfony/http-foundation/File/File.php on line 35
Steps To Reproduce:
- Set up fresh Laravel installment.
- throw the error in
vendor/symfony/http-foundation/File/File.phplike this:
public function __construct(string $path, bool $checkPath = true)
{
throw new FileNotFoundException($path);
if ($checkPath && !is_file($path)) {
}
parent::__construct($path);
}
Note: any thrown error in Request::capture() can have the same case.
my issue link in laravel repo