Review security of ExtJS iframe file upload responses (jsontext / text/html)

XMLWordPrintable

    • High
    • None
    • Enhanced content type handling to improve system security.
    • None

      Background

      Our ExtJS file upload implementation uses the legacy iframe upload mechanism instead of XHR/FormData. During code review we found in PHP Backend code the following historical comment:

      /** 
       * jsontext is needed because of fileuploads: 
       * - File Uploads cant actualy done by XHR, instead a normal form submit is used
       * - on normal file uploads a json response is handled as called directly in the browser:
       * Firefox surrounds the JSON with <pre> Text for example.
       * - this disables ExtJS to parse the JSON properly.
       * A solution is to send the JSON as text/html. The Browser doesnt modify this data.
       * ExtJS must be then be triggered to parse the response.
       * For this purpose the jsontext type is introduced.
       */ 

      To mitigate the firefox <pre> wrapping the implementation therefore returns JSON using the custom jsontext response type, which is ultimately delivered as Content-Type: text/html.

      Problem

      Returning upload responses as text/html causes the browser to load the response as an HTML document inside the hidden iframe used for the file upload.

      While this was a common workaround for older browsers, it increases the attack surface for XSS if the response ever contains attacker-controlled data (e.g. filenames, validation messages, import errors or other reflected content). The XSS vector is not critical since the attacker can attack only himself, but though it should be fixed / changed to prevent further attack vectors in the future.

      The historical Firefox <pre> wrapping issue that motivated this implementation may no longer be relevant for modern browsers.

      Goal

      Re-evaluate whether the historical text/html workaround is still required in current browsers!

      If possible, upload responses should instead be returned as:

      • Content-Type: text/plain
      • X-Content-Type-Options: nosniff

      with the existing JSON payload unchanged.

      If ExtJS still parses the response correctly, this would reduce the XSS attack surface without functional changes.

      Investigation

      • Verify how the current ExtJS version parses iframe upload responses.
      • Test upload responses with:
        • Firefox ESR
        • Chrome
        • Edge
      • Compare the behaviour of:
        • Content-Type: text/plain
        • Content-Type: text/html
      • Determine whether the historical Firefox <pre> wrapping still occurs.
      • Verify that successful uploads and server-side validation errors are still handled correctly.

      Acceptance Criteria

      • The necessity of the jsontext (text/html) workaround is documented.
      • If text/plain works across supported browsers, replace the current implementation.
      • If text/html must remain, document the technical reason and harden the response by ensuring it cannot execute active HTML or JavaScript.

      Testing

      Just ensure that fileuploads in translate5 are still working as expected.

            Assignee:
            Sasha
            Reporter:
            Thomas Lauria
            None
            None
            Thomas Lauria
            Thomas Lauria
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved:
              None
              None