Skip to content

Handle PHP upload size limits gracefully - #27

Merged
codeling merged 1 commit into
mainfrom
claude/upload-size-limit-messages
Oct 3, 2026
Merged

codeling merged 1 commit into
mainfrom
claude/upload-size-limit-messages

Conversation

@codeling

@codeling codeling commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Improve handling of file uploads that exceed PHP's upload_max_filesize and post_max_size limits by detecting these conditions and showing user-friendly error messages instead of generic security token errors.

Changes

  • Detection of oversized requests: Added check in index.php to detect when POST requests exceed post_max_size (indicated by missing $_POST and $_FILES despite non-zero CONTENT_LENGTH), returning HTTP 413 with a clear message naming the limit
  • Detection of oversized files: Added check for UPLOAD_ERR_INI_SIZE and UPLOAD_ERR_FORM_SIZE PHP upload errors, showing a message with the upload_max_filesize limit
  • Improved error messaging: Removed misleading "uploaded file too large" text from the generic security token error message, since oversized uploads are now handled separately
  • Documentation: Added section to INSTALL.md explaining PHP upload limits and how to configure web server limits (nginx client_max_body_size, Apache LimitRequestBody) to work together
  • Internationalization: Added German and English translations for the new error messages
  • Test infrastructure: Extended AppServer to support setting PHP ini values via phpIni option in server configuration
  • Integration tests: Added UploadSizeLimitTest with four test cases covering:
    • Files exceeding upload_max_filesize (40K limit)
    • Requests exceeding post_max_size (100K limit)
    • Successful uploads within limits
    • Security token validation still enforced for normal requests

Implementation details

The solution distinguishes between two size limit scenarios:

  1. Single file too large (upload_max_filesize): PHP sets $_FILES['userfile']['error'] to UPLOAD_ERR_INI_SIZE or UPLOAD_ERR_FORM_SIZE
  2. Entire request too large (post_max_size): PHP discards the entire request body, leaving $_POST and $_FILES empty despite CONTENT_LENGTH being set

Both cases now provide specific, actionable error messages to users rather than confusing them with security token errors.

https://claude.ai/code/session_01Ahgn25kLAXMcG4V7N6s6u9

Detect requests above post_max_size (empty $_POST and $_FILES) before the
CSRF check and answer 413 with the limit; show the limit for files above
upload_max_filesize instead of the generic error. Tests set PHP ini values
via the new phpIni server option. INSTALL.md documents the limits.

Fixes #18

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ahgn25kLAXMcG4V7N6s6u9
@codeling
codeling merged commit 176c7cc into main Oct 3, 2026
15 checks passed
@codeling
codeling deleted the claude/upload-size-limit-messages branch October 5, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants