Page MenuHomePhabricator

Cannot upload SVG with local color profile URL; triggers "non-local target" error on Commons
Open, LowPublic

Description

How to reproduce:

  1. Open Inkscape
  2. Draw something
  3. Set a color-profile for the file
  4. Try to upload it to commons
  5. Get error “href-Attribute <color-profile http://www.w3.org/1999/xlink:href="/usr/share/color/icc/compatiblewithadobergb1998.icc"> mit nicht-lokalem Ziel (z. B. http://, javascript: etc.) sind in SVG-Dateien nicht erlaubt.”

How to fix:
Allow URLS in <color-profile>-tags.

Event Timeline

DaBPunkt created this task.Nov 1 2015, 3:01 PM
DaBPunkt raised the priority of this task from to Low.
DaBPunkt updated the task description. (Show Details)
DaBPunkt added a project: Commons.
DaBPunkt added a subscriber: DaBPunkt.
Restricted Application added subscribers: Steinsplitter, Aklapper. · View Herald TranscriptNov 1 2015, 3:01 PM

Allow URLS in <color-profile>-tags.

Well, URLs are allowed if the URL is local. At least that's what the message implies to me.

I do not think we want to allow remote / non-local URLs due to security reasons (loading random content from a random server into an SVG).

href attribute <color-profile http://www.w3.org/1999/xlink:href="/usr/share/color/icc/compatiblewithadobergb1998.icc">

That looks rather broken (and like a bug in Inkscape) if http://wiki.inkscape.org/wiki/index.php/Adding_color-profile_element is correct.

zhuyifei1999 moved this task from Incoming to Backlog on the Commons board.Nov 2 2015, 8:55 AM

I do not think we want to allow remote / non-local URLs due to security reasons (loading random content from a random server into an SVG).

AFAIS this is not an URL for downloading, but a URL in the sense of an identifier (so more like a URI). Every SVG contains several of these.

Is that affected SVG somewhere available for download, for inspection?

@DaBPunkt: Ping. This ticket is unlikely to progress without your input. Also, is this problem actually specific to commons?

@DaBPunkt: Ping. This ticket is unlikely to progress without your input. Also, is this problem actually specific to commons?

What is expected by me? And no, I guess it is valid for all Wikimedia-wikis; but at Commons it is most urgend.

@DaBPunkt: Ping. This ticket is unlikely to progress without your input. Also, is this problem actually specific to commons?

What is expected by me? And no, I guess it is valid for all Wikimedia-wikis; but at Commons it is most urgend.

See @Aklapper's comment. Also, from the Commons project description:

Please do not report tasks under this project if the task is not actually specific to Commons but only because you found this problem on Commons. Also see How to report a bug.

See @Aklapper's comment.

There is a step-by-step in my first post. Of course I can not upload such a file to commons, because of the error.

Also, from the Commons project description:

Please do not report tasks under this project if the task is not actually specific to Commons but only because you found this problem on Commons. Also see How to report a bug.

So remove it.

There is a step-by-step in my first post. Of course I can not upload such a file to commons, because of the error.

Can you please make an affected SVG somewhere available for inspection?

Confirming.
The line in the SVG file is <color-profile xlink:href="/usr/share/color/icc/colord/AdobeRGB1998.icc" /> but the error message is
href attributes <color-profile http://www.w3.org/1999/xlink:href="/usr/share/color/icc/colord/adobergb1998.icc"> with non-local target (e.g. http://, javascript:, etc) are not allowed in SVG files.

Wondering what concatenates that URL.

Aklapper renamed this task from Color-Managment-Setting in SVGs are not allowed in Commons to Cannot upload SVG with local color profile URL; triggers "non-local target" error on Commons.Dec 30 2015, 1:51 PM