widelands-dev team mailing list archive
-
widelands-dev team
-
Mailing list archive
-
Message #17907
Re: [Merge] lp:~widelands-dev/widelands-website/pybb_attachments into lp:widelands-website
> Everyone can rename 'image.js' into 'image.png'...
That's true. It would still be an advantage though if the browser then doesn't execute it.
Doing a full validation too is definitely a better idea.
> What about restricting uploads to users who have written x posts prior?
Also a good idea
--
https://code.launchpad.net/~widelands-dev/widelands-website/pybb_attachments/+merge/370342
Your team Widelands Developers is requested to review the proposed merge of lp:~widelands-dev/widelands-website/pybb_attachments into lp:widelands-website.
References