$wgFileBlacklist should include 'xhtml'
Closed, ResolvedPublic


Author: wonder

Along with the other html filetypes, .xhtml uploads should be blacklisted by default, because they could be a threat on a WM site that uses application/xhtml+xml, or even one that doesn't.

Version: 1.16.x
Severity: normal

bzimport added projects: MediaWiki-Uploading, Easy.Via ConduitNov 21 2014, 10:39 PM
bzimport set Reference to bz19355.
bzimport created this task.Via LegacyJun 22 2009, 10:27 PM
brion added a comment.Via ConduitJul 19 2009, 7:42 PM

.xhtml and .xht added in r53487

Gilles added a project: Multimedia.Via WebDec 4 2014, 10:48 AM
Gilles moved this task to Closed on the Multimedia workboard.

Add Comment

Column Prototype
This is a very early prototype of a persistent column. It is not expected to work yet, and leaving it open will activate other new features which will break things. Press "\" (backslash) on your keyboard to close it now.