Skip to content

fix: show the correct error for folder attachments - #100706

Merged
mollfpr merged 2 commits into
Expensify:mainfrom
margelo:@chrispader/fix/single-folder-attachment-error
Sep 11, 2026
Merged

mollfpr merged 2 commits into
Expensify:mainfrom
margelo:@chrispader/fix/single-folder-attachment-error

Conversation

@chrispader

@chrispader chrispader commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Folder drops can surface misleading errors depending on where and how the user drops them. A single folder in the attachment zone falls back to corrupted-file copy, the receipt zone reports an unsupported file type, and mixed selections use a title that implies every file failed. This PR makes folder classification and error titles consistent across those paths.

Reproduction

  1. Open a report on desktop web and drag a single folder onto the attachment drop zone.
  2. Notice that the modal shows the generic corrupted-file message instead of the folder-specific message.
  3. Drag a single folder onto the receipt drop zone.
  4. Notice that the modal reports an unsupported file type instead of rejecting the folder as a folder.
  5. Drag a folder and a valid file onto the attachment drop zone together.
  6. Notice that the modal uses the singular attachment-error title even though the valid file can continue.

Explanation of Change

This originated while re-evaluating the unfinished attachment-validation work in #85751. Most of that work was later covered by #86189, which corrected receipt attachment validation, #93234, which made multi-file validation sequential and cleaned up object URLs, and #92236, which expanded useFilesValidation coverage. Related fixes in #96024 and #96940 also addressed HEIC conversion failures and file snapshot reliability.

Comparing those changes with the current implementation exposed three remaining gaps. getFileValidationErrorText() fell back to the corrupted-file copy for a single folder, receipt validation checked the extension and size before checking whether the item was a directory, and a folder in a mixed selection used the singular attachment-error title.

Folder detection now runs before receipt-specific extension and size validation. The error mapper returns the folder-specific reason for any folder and uses Some files can't be uploaded for a mixed selection. The multi-file limit case also documents why it intentionally has no single-file counterpart. Unit tests cover single and mixed folder errors plus receipt folders with and without a valid-looking extension.

Fixed Issues

$ #100707
PROPOSAL: N/A

Tests

  1. Sign in on desktop web and open any report.
  2. Drag a single folder onto the attachment drop zone.
  3. Verify an Attachment error modal appears with Uploading a folder is not allowed. Please try a different file.
  4. Verify the generic corrupted-file message does not appear.
  5. Drag a single folder onto the receipt drop zone.
  6. Verify the same folder-specific title and message appear instead of an unsupported-file-type or file-too-small error.
  7. Drag a folder and a valid file onto the attachment drop zone together.
  8. Verify the modal title is Some files can't be uploaded, the reason is the folder-specific message, and the valid file continues.
  • Verify that no errors appear in the JS console

Offline tests

  1. Go offline.
  2. Repeat steps 1 through 8 from Tests.
  3. Verify the same folder-specific errors appear and the valid file in the mixed selection continues.

QA Steps

Same as Tests.

  • Verify that no errors appear in the JS console

PR Author Checklist

  • I linked the correct issue in the ### Fixed Issues section above
  • I wrote clear testing steps that cover the changes made in this PR
    • I added steps for local testing in the Tests section
    • I added steps for the expected offline behavior in the Offline steps section
    • I added steps for Staging and/or Production testing in the QA steps section
    • I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
    • I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
  • I included screenshots or videos for tests on all platforms
  • I ran the tests on all platforms & verified they passed on:
    • Android: Native
    • Android: mWeb Chrome
    • iOS: Native
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
  • I followed proper code patterns (see Reviewing the code)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I followed the guidelines as stated in the Review Guidelines
  • I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
  • If new assets were added or existing ones were modified, I verified that:
    • The assets are optimized and compressed (for SVG files, run npm run compress-svg)
    • The assets load correctly across all supported platforms.
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.

Screenshots/Videos

Screenshots are provided by C+ review already

@chrispader

Copy link
Copy Markdown
Contributor Author

@MelvinBot create a GH issue for this PR and assign me to it. Update the PR description to link to this issue.

@MelvinBot

MelvinBot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Done — created #100707 and assigned chrispader.

Issue: Single folder attachment shows the generic corrupted-file error instead of the folder-specific error

I also updated this PR description:

  • ### Fixed Issues now links the new issue.
  • Checked the "I linked the correct issue" box in the author checklist.

I searched both Expensify/App and Expensify/Expensify for open and recently closed duplicates and found none.


view run · view recording

@chrispader
chrispader marked this pull request as ready for review September 9, 2026 12:30
@chrispader
chrispader requested review from a team as code owners September 9, 2026 12:30
@melvin-bot
melvin-bot Bot requested review from heyjennahay and ikevin127 and removed request for a team September 9, 2026 12:30
@melvin-bot

melvin-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown

@ikevin127 Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button]

@melvin-bot
melvin-bot Bot removed the request for review from a team September 9, 2026 12:30
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-09T12:40:29.880401Z 3aa1f54 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ikevin127

ikevin127 commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Reviewer Checklist

  • I have verified the author checklist is complete (all boxes are checked off).
  • I verified the correct issue is linked in the ### Fixed Issues section above
  • I verified testing steps are clear and they cover the changes made in this PR
    • I verified the steps for local testing are in the Tests section
    • I verified the steps for Staging and/or Production testing are in the QA steps section
    • I verified the steps cover any possible failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
  • I checked that screenshots or videos are included for tests on all platforms
  • I included screenshots or videos for tests on all platforms
  • I verified that the composer does not automatically focus or open the keyboard on mobile unless explicitly intended. This includes checking that returning the app from the background does not unexpectedly open the keyboard.
  • I verified tests pass on all platforms & I tested again on:
    • Android: HybridApp
    • Android: mWeb Chrome
    • iOS: HybridApp
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • If there are any errors in the console that are unrelated to this PR, I either fixed them (preferred) or linked to where I reported them in Slack
  • I verified proper code patterns were followed (see Reviewing the code)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I verified that this PR follows the guidelines as stated in the Review Guidelines
  • I verified other components that can be impacted by these changes have been tested, and I retested again (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar have been tested & I retested again)
  • If a new component is created I verified that:
    • A similar component doesn't exist in the codebase
    • All props are defined accurately
    • The component has a clear name that is non-ambiguous and the purpose of the component can be inferred from the name alone
    • The only data being stored in the state is data necessary for rendering and nothing else
    • The component has the minimum amount of code necessary for its purpose, and it is broken down into smaller components in order to separate concerns and functions
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG)
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • For any bug fix or new feature in this PR, I verified that sufficient unit tests are included to prevent regressions in this flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.
  • I have checked off every checkbox in the PR reviewer checklist, including those that don't apply to this PR.

Screenshots/Videos

Screen.Recording.2026-09-10.at.17.04.55.mov

@ikevin127

Copy link
Copy Markdown
Contributor

🟡 The receipt drop flow still shows the wrong error for a single folder, so the fix is only half the story

src/libs/validateAttachmentFile.ts:26 runs the receipt extension check before the directory check:

if (isValidatingReceipts && !isValidReceiptExtension(file)) {
    return {isValid: false, error: CONST.FILE_VALIDATION_ERRORS.WRONG_FILE_TYPE};
}
// ...
if (isValidatingReceipts && file.size < CONST.API_ATTACHMENT_VALIDATIONS.MIN_SIZE) {
    return {isValid: false, error: CONST.FILE_VALIDATION_ERRORS.FILE_TOO_SMALL};
}
// ...
if (isDataTransferItemDirectory(item)) {   // never reached for receipts
    return {isValid: false, error: CONST.FILE_VALIDATION_ERRORS.FOLDER_NOT_ALLOWED};
}

A dropped folder has no extension, so isValidReceiptExtension() returns false and we bail with WRONG_FILE_TYPE before isDataTransferItemDirectory() ever runs. Even if the folder happened to be named receipts.pdf, its size is 0, which is under MIN_SIZE: 240, so it would bail with FILE_TOO_SMALL next.

useReceiptDrop.ts:127 calls validateFiles(files, items, {isValidatingReceipts: true}), so this is a live path: drag one folder onto a money request receipt drop zone today and you get "The selected file type is not supported" plus the "Learn more about supported files" link, not the folder copy this PR is about.

Bug in the app: user drags a folder onto the receipt zone, gets told the file type is unsupported, and reasonably tries renaming or converting the folder instead of learning that folders are simply not accepted. Same confusion the linked issue describes, just in a different entry point.

Suggested fix, hoist the directory check above the receipt-specific checks:

async function validateAttachmentFile(file: FileObject, item?: DataTransferItem, isValidatingReceipts = false): Promise<ValidateAttachmentResult> {
    if (!file.name || file.size == null) {
        return {isValid: false, error: CONST.FILE_VALIDATION_ERRORS.FILE_INVALID};
    }

    // A folder is never a valid attachment, so classify it before any extension or size checks.
    // Otherwise receipt validation rejects it as WRONG_FILE_TYPE (no extension) or FILE_TOO_SMALL (size 0).
    if (isDataTransferItemDirectory(item)) {
        return {isValid: false, error: CONST.FILE_VALIDATION_ERRORS.FOLDER_NOT_ALLOWED};
    }

    if (isValidatingReceipts && !isValidReceiptExtension(file)) {
        // ...

Note this needs isDataTransferItemDirectory() to move above validateAttachmentFile or stay a hoisted function declaration (it already is one, so it works as written). The getAsFile() / fileConverted block below is unaffected because the directory check only reads item, not fileObject.

@chrispader If you'd rather keep this PR scoped to the issue, that's fine, but please call it out in the description or spin off a follow-up issue, because the PR title reads like all single-folder entry points are covered and they aren't.

Comment thread src/libs/fileDownload/FileUtils.ts
@ikevin127

Copy link
Copy Markdown
Contributor

🟢 Optional: the multi-item folder error keeps the singular title

The other multi-file errors use someFilesCantBeUploaded, folder now resolves to attachmentError for both single and multi. Dropping folder/ plus receipt.png reads as though the whole drop failed, even though receipt.png still uploads. Pre-existing and not a regression from this diff, and it's a copy change needing sign-off, so entirely your call whether to touch it here.

@ikevin127 ikevin127 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 LGTM - Small change, tests well - only 3 non-blocking comments.

@melvin-bot

melvin-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown

We did not find an internal engineer to review this PR, trying to assign a random engineer to #100707 as well as to this PR... Please reach out for help on Slack if no one gets assigned!

@melvin-bot
melvin-bot Bot requested a review from mollfpr September 11, 2026 00:07
@chrispader chrispader changed the title fix: show the correct error for a single folder attachment [WIP] fix: show the correct error for folder attachments Sep 11, 2026
@chrispader

Copy link
Copy Markdown
Contributor Author

@ikevin127 I addressed all three comments in 0068823.

  • Folder detection now runs before receipt extension and size checks. The regression test covers an extensionless folder and a folder named receipts.pdf.
  • Mixed selections use Some files can't be uploaded, while a single folder keeps Attachment error.
  • The max-file-limit case now explains why it intentionally exists only in the multi-file branch.

I also broadened the PR title, description, and manual test steps to cover the receipt and mixed-selection paths. The PR is marked WIP until the expanded flow is retested.

Answered by Codex, instructed by Chris.

@chrispader chrispader changed the title [WIP] fix: show the correct error for folder attachments fix: show the correct error for folder attachments Sep 11, 2026
@mollfpr
mollfpr merged commit 400981c into Expensify:main Sep 11, 2026
36 of 38 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

🚧 mollfpr has triggered a test Expensify/App build. You can view the workflow run here.

@OSBotify

Copy link
Copy Markdown
Contributor

✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release.

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to staging by https://github.com/mollfpr in version: 9.4.77-0 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

@MelvinBot

MelvinBot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

🤖 No help site changes are required for this PR — I did not create a docs PR.

This PR only corrects which in-app error title and reason are shown when a folder is dropped. It does not change what users can do, any setting, tab, label, or button, and it does not change the folder restriction itself — folders were already rejected before this PR.

How I checked

What changed: getFileValidationErrorText() now returns the folder-specific reason for both single and mixed selections, and validateAttachmentFile() detects directories before the receipt extension and size checks. The strings themselves already exist and are unchanged: src/languages/en.ts:610 and src/languages/en.ts:617.

What I searched in docs/articles:

Because no published article states the old behavior, there is nothing to correct. Adding a new FAQ about folder uploads would document a pre-existing restriction rather than this change, so it is outside the scope of a docs update for this PR.

chrispader, since no help site content becomes inaccurate from this change, there is no linked docs PR to review. If you want a standalone FAQ added about folder uploads — for example, under Attach and edit receipts on expenses — reply and I'll open the draft PR for it.


view run · no recording available

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to production by https://github.com/luacmartins in version: 9.4.77-4 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

Bundle Size Analysis (Sentry):

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants