CM

Site: Can upload invalid formats for preview

Bug #774150 reported by Gregory.Yeung
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
CM
Fix Released
High
Jacky Li

Bug Description

.doc file for example

Changed in cm:
assignee: nobody → Jacky Li (jackylisiukwan)
Revision history for this message
rejon (rejon) wrote : Re: [Bug 774150] Re: Site: Can upload invalid formats for preview

What kind of files? Type and size?

<email address hidden>
http://fabricatorz.com
On Apr 30, 2011 12:46 PM, "Jacky Li" <email address hidden> wrote:
> ** Changed in: cm
> Assignee: (unassigned) => Jacky Li (jackylisiukwan)
>
> --
> You received this bug notification because you are a member of CM
> Developers, which is subscribed to CM.
> https://bugs.launchpad.net/bugs/774150
>
> Title:
> Site: Can upload invalid formats for preview

Revision history for this message
Bassel Safadi (bassel) wrote :

mime types should be checked after upload. where are the settings for allowed extensions?

Changed in cm:
status: New → Confirmed
importance: Undecided → High
milestone: none → milestone-2011-05
Changed in cm:
status: Confirmed → Fix Released
Revision history for this message
rejon (rejon) wrote :

also, should be noted that mime-type detection is spoofable as well...more security should be added, but this is enough for now. good work!

Revision history for this message
Jacky Li (jackylisiukwan) wrote :

I hope the following definition gives can explain:

FOR ALL content-type IN ['video/*', 'image/*', 'audio/*']

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.