-
-
Notifications
You must be signed in to change notification settings - Fork 6
Add the ability to restrict max avatar filesize and content-type #19
Conversation
Sytests are failing until sytest-synapse:dinsic docker is fixed. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just some tidying up really, nothing major.
synapse/handlers/profile.py
Outdated
): | ||
# Parse the media URI | ||
try: | ||
media_id = new_avatar_url.split("/")[-1] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This never actually throws btw, since .split
will always return at least one thing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this is what I was looking for with the ValueError
:
try:
_, media_id = new_avatar_url.split("/")
except ValueError:
raise SynapseError(400, "Invalid avatar URL '%s' supplied" %
new_avatar_url)
# | ||
# Note that this only applies to when an avatar is changed globally. | ||
# Per-room avatar changes are not affected. See allow_per_room_profiles | ||
# for disabling that functionality. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this OK for dinsic?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
They currently have per-room avatar functionality disabled, thus all avatar changes must be made globally, which the new option will gatekeep.
Only allow files which file size and content types match configured limits to be set as avatar. Most of the inspiration from the non-test code comes from matrix-org/synapse-dinsic#19
Only allow files which file size and content types match configured limits to be set as avatar. Most of the inspiration from the non-test code comes from #19
Add an option to prevent users from changing their avatar to something that's greater than a maximum size and/or is not a within a whitelist of file mimetypes.