Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Filenames without extensions not being properly handled #56

Open
ghost opened this issue Dec 9, 2016 · 2 comments
Open

Filenames without extensions not being properly handled #56

ghost opened this issue Dec 9, 2016 · 2 comments
Labels

Comments

@ghost
Copy link

ghost commented Dec 9, 2016

Uploading images which filenames lack the extension seem to not be handled which causes lapis-chan to crash.

I'm kind of sure why it is happening and who to blame (I'm looking at you, yes you!) so this is more related to what to do with no-extension filenames rather than tweak some buggy code (although the latter is a must).

As a suggestion I think checking for image format headers won't hurt much :).

@karai17
Copy link
Owner

karai17 commented Dec 9, 2016

Thanks, I know exactly what the issue is. As for format headers, I recall hearing that those aren't very reliable. Or maybe I am thinking of mime types. Anyway, I'd rather reject a malformed file than try to find a way to get it on the site. Attack vector, etc.

@karai17 karai17 added the bug label Dec 9, 2016
@ghost
Copy link
Author

ghost commented Dec 9, 2016

Good, let yourself be more secure and let the world get more conscious.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant