Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Users can upload any file as PWA Firebase JSON config #62

Open
SKevo18 opened this issue Oct 18, 2024 · 0 comments
Open

Users can upload any file as PWA Firebase JSON config #62

SKevo18 opened this issue Oct 18, 2024 · 0 comments

Comments

@SKevo18
Copy link

SKevo18 commented Oct 18, 2024

For context, I have just had an user upload a PNG image as the Firebase config, which prevented the Flarum JSON payload from rendering altogether, making the admin panel load infinitely even after all extensions have been disabled. Manually clearing the file from the settings in the DB fixes the issue.

I am not sure how is the file parsed exactly, but I feel like there should be some handler for edge cases like this (perhaps by checking mimetypes, etc.?)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant