Allow uploading of SVG files to the wiki

Bug #1823611 reported by GunChleoc
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Widelands Website
Won't Fix
Low
Unassigned

Bug Description

I have uploaded some flowcharts to https://wl.widelands.org/wiki/GitPrimer/

I had to use PNG but would prefer SVG, because it will give us better quality and save on server space + bandwidth.

kaputtnik (franku)
Changed in widelands-website:
status: New → Confirmed
Revision history for this message
kaputtnik (franku) wrote :

I have tried to gather some information about svg files and it looks to me that allowing svg files in the wiki can be dangerous. The main reason is: svg are xml files and can be manipulated by javascript in the same manner as a normal html document. More over svg files are allowed to contain script in it self.

This are mainly the reasons why djngo doesn't support it: https://code.djangoproject.com/ticket/14092

Why wordpress doesn't allow uplading svg files, with scripting example
https://bjornjohansen.no/svg-in-wordpress

So if we really want this, uploading svg files should only be allowed for trusted users (e.g. admins), imho.

Revision history for this message
GunChleoc (gunchleoc) wrote :

Let's scrap this idea then - we won't want to have to deal with potential JavaScript here.

Changed in widelands-website:
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.