moodle-tool_objectfs icon indicating copy to clipboard operation
moodle-tool_objectfs copied to clipboard

Have a giant warning for signed urls not to be used for file types which can include relative paths

Open brendanheywood opened this issue 4 years ago • 3 comments

ie html, css, maybe js, anything which contains a relative url which is no fully qualified will break when signed and loading the dependancies

brendanheywood avatar Jun 28 '20 23:06 brendanheywood

Should we just exclude those file types and not rely on users?

dmitriim avatar Jun 28 '20 23:06 dmitriim

For the list of known filetypes yes, but there could be a long tail of weird unknown ones.

brendanheywood avatar Jun 29 '20 00:06 brendanheywood

Also, even if we exclude those files, the issue remains if those files then point to whitelisted filetypes that have been deleted from local storage but kept on object fs.

vrioux avatar Oct 08 '21 02:10 vrioux