Merge pull request from GHSA-9928-3cp5-93fm
* Fix attachments getting processed despite failing content-type validation * Add a restrictive ImageMagick security policy tailored for Mastodon * Fix misdetection of MP3 files with large cover art * Reject unprocessable audio/video files instead of keeping them unchanged
Showing
- app/models/concerns/attachmentable.rb 2 additions, 3 deletionsapp/models/concerns/attachmentable.rb
- config/application.rb 1 addition, 0 deletionsconfig/application.rb
- config/imagemagick/policy.xml 27 additions, 0 deletionsconfig/imagemagick/policy.xml
- config/initializers/paperclip.rb 7 additions, 0 deletionsconfig/initializers/paperclip.rb
- lib/paperclip/media_type_spoof_detector_extensions.rb 22 additions, 0 deletionslib/paperclip/media_type_spoof_detector_extensions.rb
- lib/paperclip/transcoder.rb 1 addition, 4 deletionslib/paperclip/transcoder.rb
- spec/fixtures/files/boop.mp3 0 additions, 0 deletionsspec/fixtures/files/boop.mp3
- spec/models/media_attachment_spec.rb 20 additions, 0 deletionsspec/models/media_attachment_spec.rb
Loading
Please register or sign in to comment