This repository has been archived by the owner on Feb 15, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 11
ability to blacklist certain types of files (eg. swf) #5
Labels
Comments
Is this still relevant? I haven't found a line that allows the mirroring of attachments. Am I overlooking something? |
Unfortunately I don't really remember. I think this was actually when we migrated from Trac to Github and we synced/copied the attachments from Trac to make sure we still have them but I may be wrong. |
Yes it is still relevant, would like to blacklist file extensions
especially Flash SWF because it can be used to trigger an XSS currently.
|
Hi, I understand why swf files should be excluded, but I don't know where the attachments come from as I haven't found a corresponding piece of code. |
Yep I don't think we download any attachment. As far as I know we only kept some attachments from Trac but not 1000% sure :) |
https://issues.piwik.org/1199 links to them so I guess I’ll just remove any link in the form of /attachments/*.swf |
👍 |
Findus23
added a commit
to Findus23/github-issues-mirror
that referenced
this issue
Sep 21, 2017
Merged
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
The goal of this issue is to add a blacklist of filetypes, that should not be mirrored in the github issues mirror. We could set the default blacklist to
swf
to exclude flash files from being synched.Why? this is a security improvement. We received this report:
blacklisting some file types would help minimise such XSS vulnerability.
The text was updated successfully, but these errors were encountered: