glpi-project / glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
https://glpi-project.org
GNU General Public License v3.0
4.15k stars 1.28k forks source link

Description gets lost if inline image is fairly big #17622

Closed valentindragan closed 1 month ago

valentindragan commented 1 month ago

Code of Conduct

Is there an existing issue for this?

Version

10.16

Bug description

While trying to reproduce a bug I encountered on 10.07 with (huge) blob files getting stored inside description field, while i was not able to reproduce that, i discovered a new bug. I have installed a fresh copy of GLPI 10.16 on a PHP8 environment and also on a php7.4 env (same results)

Case 1:

In both cases, the entire description gets lost. Even the text. In case 2, the ticket gets created, only the description is empty.

Screenshot_32 Screenshot_33

Yellow_Flower_Background-517

Relevant log output

No response

Page URL

No response

Steps To reproduce

Case 1:

In both cases, the entire description gets lost. Even the text. In case 2, the ticket gets created, only the description is empty.

Your GLPI setup information

Information about system installation & configuration --   GLPI 10.0.16 ( => /var/www/html/glpi10168/backend) Installation mode: TARBALL Current language:en_US Operating system: Linux wscentos7-php8.localdomain 3.10.0-1160.118.1.el7.x86_64 #​1 SMP Wed Apr 24 16:01:50 UTC 2024 x86_64 PHP 8.1.29 apache2handler (Core, PDO, Phar, Reflection, SPL, SimpleXML, Zend OPcache, apache2handler, bz2, calendar, ctype, curl, date, dom, exif, fileinfo, filter, ftp, gd, gettext, hash, iconv, intl, json, libxml, mbstring, mysqli, mysqlnd, openssl, pcre, pdo_mysql, pdo_sqlite, session, sockets, sodium, sqlite3, standard, tokenizer, xml, xmlreader, xmlwriter, xsl, zip, zlib) Setup: max_execution_time="30" memory_limit="128M" post_max_size="8M" safe_mode="" session.save_handler="files" upload_max_filesize="2M" disable_functions="" Software: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/8.1.29 () Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 Server Software: MariaDB Server Server Version: 10.6.16-MariaDB Server SQL Mode: STRICT_TRANS_TABLES,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION Parameters: root@localhost/glpi10168 Host info: Localhost via UNIX socket PHP version (8.1.29) is supported. Sessions configuration is OK. Allocated memory is sufficient. mysqli extension is installed. Following extensions are installed: dom, fileinfo, filter, libxml, json, simplexml, xmlreader, xmlwriter. curl extension is installed. gd extension is installed. intl extension is installed. zlib extension is installed. The constant SODIUM_CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES is present. Database engine version (10.6.16) is supported. No files from previous GLPI version detected. The log file has been created successfully. Write access to /var/www/html/glpi10168/backend/files/_cache has been validated. Write access to /var/www/html/glpi10168/backend/files/_cron has been validated. Write access to /var/www/html/glpi10168/backend/files has been validated. Write access to /var/www/html/glpi10168/backend/files/_dumps has been validated. Write access to /var/www/html/glpi10168/backend/files/_graphs has been validated. Write access to /var/www/html/glpi10168/backend/files/_lock has been validated. Write access to /var/www/html/glpi10168/backend/files/_pictures has been validated. Write access to /var/www/html/glpi10168/backend/files/_plugins has been validated. Write access to /var/www/html/glpi10168/backend/files/_rss has been validated. Write access to /var/www/html/glpi10168/backend/files/_sessions has been validated. Write access to /var/www/html/glpi10168/backend/files/_tmp has been validated. Write access to /var/www/html/glpi10168/backend/files/_uploads has been validated. For security reasons, SELinux mode should be Enforcing. Web server root directory configuration seems safe. PHP directive "session.cookie_secure" should be set to "on" when GLPI can be accessed on HTTPS protocol. PHP directive "session.cookie_httponly" should be set to "on" to prevent client-side script to access cookie values. OS and PHP are relying on 64 bits integers. exif extension is installed. ldap extension is not present. openssl extension is installed. Following extensions are installed: bz2, Phar, zip. Zend OPcache extension is installed. Following extensions are installed: ctype, iconv, mbstring, sodium. The directory could not be created in /var/www/html/glpi10168/backend/marketplace. Timezones seems not loaded, see https://glpi-install.readthedocs.io/en/latest/timezones.html. GLPI_ROOT: "/var/www/html/glpi10168/backend" GLPI_CONFIG_DIR: "/var/www/html/glpi10168/backend/config" GLPI_VAR_DIR: "/var/www/html/glpi10168/backend/files" GLPI_MARKETPLACE_DIR: "/var/www/html/glpi10168/backend/marketplace" GLPI_USE_CSRF_CHECK: "1" GLPI_CSRF_EXPIRES: "7200" GLPI_CSRF_MAX_TOKENS: "100" GLPI_USE_IDOR_CHECK: "1" GLPI_IDOR_EXPIRES: "7200" GLPI_ALLOW_IFRAME_IN_RICH_TEXT: false GLPI_SERVERSIDE_URL_ALLOWLIST: ["/^(https?\|feed):\\/\\/[^@:]+(\\/.*)?$/"] GLPI_TELEMETRY_URI: "https://telemetry.glpi-project.org" GLPI_INSTALL_MODE: "TARBALL" GLPI_NETWORK_MAIL: "glpi@teclib.com" GLPI_NETWORK_SERVICES: "https://services.glpi-network.com" GLPI_MARKETPLACE_ALLOW_OVERRIDE: true GLPI_MARKETPLACE_MANUAL_DOWNLOADS: true GLPI_USER_AGENT_EXTRA_COMMENTS: "" GLPI_DISABLE_ONLY_FULL_GROUP_BY_SQL_MODE: "1" GLPI_AJAX_DASHBOARD: "1" GLPI_CALDAV_IMPORT_STATE: 0 GLPI_DEMO_MODE: "0" GLPI_CENTRAL_WARNINGS: "1" GLPI_TEXT_MAXSIZE: "4000" GLPI_DOC_DIR: "/var/www/html/glpi10168/backend/files" GLPI_CACHE_DIR: "/var/www/html/glpi10168/backend/files/_cache" GLPI_CRON_DIR: "/var/www/html/glpi10168/backend/files/_cron" GLPI_DUMP_DIR: "/var/www/html/glpi10168/backend/files/_dumps" GLPI_GRAPH_DIR: "/var/www/html/glpi10168/backend/files/_graphs" GLPI_LOCAL_I18N_DIR: "/var/www/html/glpi10168/backend/files/_locales" GLPI_LOCK_DIR: "/var/www/html/glpi10168/backend/files/_lock" GLPI_LOG_DIR: "/var/www/html/glpi10168/backend/files/_log" GLPI_PICTURE_DIR: "/var/www/html/glpi10168/backend/files/_pictures" GLPI_PLUGIN_DOC_DIR: "/var/www/html/glpi10168/backend/files/_plugins" GLPI_RSS_DIR: "/var/www/html/glpi10168/backend/files/_rss" GLPI_SESSION_DIR: "/var/www/html/glpi10168/backend/files/_sessions" GLPI_TMP_DIR: "/var/www/html/glpi10168/backend/files/_tmp" GLPI_UPLOAD_DIR: "/var/www/html/glpi10168/backend/files/_uploads" GLPI_INVENTORY_DIR: "/var/www/html/glpi10168/backend/files/_inventories" GLPI_NETWORK_REGISTRATION_API_URL: "https://services.glpi-network.com/api/registration/" GLPI_MARKETPLACE_PLUGINS_API_URI: "https://services.glpi-network.com/api/marketplace/" GLPI_I18N_DIR: "/var/www/html/glpi10168/backend/locales" GLPI_VERSION: "10.0.16" GLPI_SCHEMA_VERSION: "10.0.16@b13256c443dd4fdb27b4a0d3b8fea8caba4dfaa9" GLPI_MARKETPLACE_PRERELEASES: false GLPI_MIN_PHP: "7.4.0" GLPI_MAX_PHP: "8.4.0" GLPI_YEAR: "2024" htmlawed/htmlawed version 1.2.14 in (/var/www/html/glpi10168/backend/vendor/htmlawed/htmlawed) phpmailer/phpmailer version 6.8.0 in (/var/www/html/glpi10168/backend/vendor/phpmailer/phpmailer/src) simplepie/simplepie version 1.5.8 in (/var/www/html/glpi10168/backend/vendor/simplepie/simplepie/library) tecnickcom/tcpdf version 6.7.5 in (/var/www/html/glpi10168/backend/vendor/tecnickcom/tcpdf) michelf/php-markdown in (/var/www/html/glpi10168/backend/vendor/michelf/php-markdown/Michelf) true/punycode in (/var/www/html/glpi10168/backend/vendor/true/punycode/src) iamcal/lib_autolink in (/var/www/html/glpi10168/backend/vendor/iamcal/lib_autolink) sabre/dav in (/var/www/html/glpi10168/backend/vendor/sabre/dav/lib/DAV) sabre/http in (/var/www/html/glpi10168/backend/vendor/sabre/http/lib) sabre/uri in (/var/www/html/glpi10168/backend/vendor/sabre/uri/lib) sabre/vobject in (/var/www/html/glpi10168/backend/vendor/sabre/vobject/lib) laminas/laminas-i18n in (/var/www/html/glpi10168/backend/vendor/laminas/laminas-i18n/src) laminas/laminas-servicemanager in (/var/www/html/glpi10168/backend/vendor/laminas/laminas-servicemanager/src) monolog/monolog in (/var/www/html/glpi10168/backend/vendor/monolog/monolog/src/Monolog) sebastian/diff in (/var/www/html/glpi10168/backend/vendor/sebastian/diff/src) donatj/phpuseragentparser in (/var/www/html/glpi10168/backend/vendor/donatj/phpuseragentparser/src/UserAgent) elvanto/litemoji in (/var/www/html/glpi10168/backend/vendor/elvanto/litemoji/src) symfony/console in (/var/www/html/glpi10168/backend/vendor/symfony/console) scssphp/scssphp in (/var/www/html/glpi10168/backend/vendor/scssphp/scssphp/src) laminas/laminas-mail in (/var/www/html/glpi10168/backend/vendor/laminas/laminas-mail/src/Protocol) laminas/laminas-mime in (/var/www/html/glpi10168/backend/vendor/laminas/laminas-mime/src) rlanvin/php-rrule in (/var/www/html/glpi10168/backend/vendor/rlanvin/php-rrule/src) ramsey/uuid in (/var/www/html/glpi10168/backend/vendor/ramsey/uuid/src) psr/log in (/var/www/html/glpi10168/backend/vendor/psr/log/Psr/Log) psr/simple-cache in (/var/www/html/glpi10168/backend/vendor/psr/simple-cache/src) psr/cache in (/var/www/html/glpi10168/backend/vendor/psr/cache/src) league/csv in (/var/www/html/glpi10168/backend/vendor/league/csv/src) mexitek/phpcolors in (/var/www/html/glpi10168/backend/vendor/mexitek/phpcolors/src/Mexitek/PHPColors) guzzlehttp/guzzle in (/var/www/html/glpi10168/backend/vendor/guzzlehttp/guzzle/src) guzzlehttp/psr7 in (/var/www/html/glpi10168/backend/vendor/guzzlehttp/psr7/src) glpi-project/inventory_format in (/var/www/html/glpi10168/backend/vendor/glpi-project/inventory_format/lib/php) wapmorgan/unified-archive in (/var/www/html/glpi10168/backend/vendor/wapmorgan/unified-archive/src) paragonie/sodium_compat in (/var/www/html/glpi10168/backend/vendor/paragonie/sodium_compat/src) symfony/cache in (/var/www/html/glpi10168/backend/vendor/symfony/cache) html2text/html2text in (/var/www/html/glpi10168/backend/vendor/html2text/html2text/src) symfony/css-selector in (/var/www/html/glpi10168/backend/vendor/symfony/css-selector) symfony/dom-crawler in (/var/www/html/glpi10168/backend/vendor/symfony/dom-crawler) twig/twig in (/var/www/html/glpi10168/backend/vendor/twig/twig/src) twig/string-extra in (/var/www/html/glpi10168/backend/vendor/twig/string-extra) symfony/polyfill-ctype not found symfony/polyfill-iconv not found symfony/polyfill-mbstring not found symfony/polyfill-php80 not found symfony/polyfill-php81 not found symfony/polyfill-php82 in (/var/www/html/glpi10168/backend/vendor/symfony/polyfill-php82) league/oauth2-client in (/var/www/html/glpi10168/backend/vendor/league/oauth2-client/src/Provider) league/oauth2-google in (/var/www/html/glpi10168/backend/vendor/league/oauth2-google/src/Provider) thenetworg/oauth2-azure in (/var/www/html/glpi10168/backend/vendor/thenetworg/oauth2-azure/src/Provider) Not active Way of sending emails: PHP    

Anything else?

No response

cedric-anne commented 1 month ago

Duplicates #16444.

It will be fix in GLPI 11.0 (the library responsible of the rich text parsing changed, but it is a bit hard to backport to GLPI 10.0).

As a workaround, you can increase the pcre.backtrack_limit PHP configuration value to handle larger images, but there would still be a hard limit.

valentindragan commented 1 month ago

Most of the GLPI version 10 or higher have had problems with the inline drag and drop images inside WYSIWYG description, either it was this, of the remaining blob inside the database. It would be great if the feature can be turned off completely in feature versions. As a workaround, in 10.07 i have added the paste_block_drop: true, option to the tinyMCE.init(Object.assign({ ............ ++paste_block_drop: true, ..............}) inside the public static function initEditorSystem in the /src/Html.php file

That would disable drag and drop images, while the user can still upload via drag and drop onto the upload input container. The images already uploaded correctly would still be displayed as intended, and the users could still use external images inside description. I would recommend this workaround for this issue as well for whomever would like to ditch the feature completely.

Also for whomever is in charge of developing this feature, GitHub handles this inline uploads wonderfully, in the very editor I am writing this.