- 🇩🇪Germany Duwid
These two tickets are related but not duplicates. In #3271758, the file is validated, and a call to social_profile_get_default_image() is prevented. However, social_profile_get_default_image() is called in multiple places, e.g., by EmailTokenServices::getUserPreview(). As wassper correctly assumed, a check is needed to see if the file exists in social_profile_get_default_image().
Here is a new approach for open_social 12.