XSS validation on upload and not only display

Created on 12 November 2024, 14 days ago

Hello,

This issue https://www.drupal.org/project/svg_image/issues/3006135 was asking for validation of XSS on svg uploads.

This is well implemented on Drupal\svg_image\Plugin\Field\FieldFormatter\SvgImageFormatter with sanitize method in fileGetContents.

Is it possible to add a validator on SVG media upload that would reject the upload or modify the file before storing it ? This would avoid to have a malicious file on server and protect user if the svg file is accessed directly.

I could provide a patch later if needed, I've not that much time currently.

Thank you !

Feature request
Status

Active

Version

3.0

Component

Code

Created by

🇫🇷France amaloisel

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024