Helix Ultimate 2.2.9 bug invalid path in Windows OS - Forum | JoomShaper
Staff replied Helix Framework

Helix Ultimate 2.2.9 bug invalid path in Windows OS

Asked by Alvaro 1 month ago Last activity 1 month ago

If you have a Windows operating system and want to select an image in Helix, and you need to access a folder to do so, you'll see the following message:
"The most recent request was denied because it had an invalid security token. Please refresh the page and try again." While the problem appears to be the security token, our investigation revealed the issue to be "Invalid media path." This led us to helper.php, specifically to the resolveMediaPath method on line 957, which contains:

if ($fullPath === $allowedPath || strpos($fullPath, $allowedPath . '/') === 0) {

To fix this bug, it should be changed to:

if ($fullPath === $allowedPath || strpos($fullPath, $allowedPath . DIRECTORY_SEPARATOR) === 0) {

Or, you can implement the same fix found in Media.php using str_replace.

I hope this solution is included in a new version as soon as possible; we Windows lovers are suffering from it.
Regards

4 replies

Atick Eashrak Shuvo Staff

Hello Alvaro,

We sincerely apologize for the inconvenience. Thank you for providing such detailed information about the issue and the potential fix.

I have forwarded the issue and your findings to our development team for further investigation. We will work to have this fixed in an upcoming update.

We greatly appreciate your patience and understanding while we work on resolving this issue.

Alvaro Asked this

This issue isn't fixed in version 2.2.10. I told them the file (helper.php) and the method (resolveMediaPath), even the line to modify and how to fix it, although you might have had better solutions, but the goal was to find a solution.

I had told the clients that I had already reported the bug and provided a temporary fix by patching their files, and now they're reporting that it no longer works after updating.

Those who work on Windows, please fix this.

Alvaro Asked this

Please, I need to know what actions you are going to take regarding this problem.

Atick Eashrak Shuvo Staff

We sincerely apologize for the inconvenience caused.

The issue has been identified, and it is planned to be fixed in the upcoming update. Please note that the previous update was released exclusively as a security update and therefore did not include bug fixes or other functional changes.

We appreciate your patience and understanding while our team works on resolving this issue.

Log in to reply.