Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restrict rename #56

Open
dvdp opened this issue Jul 24, 2015 · 3 comments
Open

Restrict rename #56

dvdp opened this issue Jul 24, 2015 · 3 comments

Comments

@dvdp
Copy link

dvdp commented Jul 24, 2015

First of all - what a great extension ! This really should be the default joomla media manager !

My remark: you need to disable safe mode to allow renaming of files and folders. I 'm using this extension e.g. for blog intro and full article image upload and creation: upload the image - resize if needed and then make a copy and size it down to thumbnail size (= intro image). Super easy, but I want to rename the copied image to <imagename)_intro.jpg so I need to disable safe mode.
With safe mode disabled, someone could upload a fake image and then rename it to e.g. .php which is a security risk so my question is: why not provide a mode that forces to keep the same file name extension. That way, one can only change something.jpg to anythingelse.jpg. Looks to me like a simple change and it provides some extra security.

@asika32764
Copy link
Member

ARI use elFinder as core image manager, so the function that rename file but keep extension name is up to elFinder. Unfortunately It seems elFinder does not provider this feature so I can't do that.

@dvdp
Copy link
Author

dvdp commented Jul 27, 2015

Hi Simon,

What about the 'acceptedName' elFinder connector option ?
If that option could be set from the RemoteImage configuration
page, one can control the names of new files I think ..

br
Danny

----- Oorspronkelijk bericht -----

Van: "Simon Asika" [email protected]
Aan: "asikart/remoteimage" [email protected]
Cc: "dvdp" [email protected]
Verzonden: Zaterdag 25 juli 2015 18:48:36
Onderwerp: Re: [remoteimage] Restrict rename (#56)

ARI use elFinder as core image manager, so the function that rename file but keep extension name is up to elFinder. Unfortunately It seems elFinder does not provider this feature so I can't do that.


Reply to this email directly or view it on GitHub .

@asika32764
Copy link
Member

I have to research for this option, I have long time not see connector's code.

If it's works, I will update it.

Thank you for this information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants