Project

General

Profile

Actions

Feature #20008

closed

Files upload Restriction by files extensions

Added by Varadharajan Sundaram almost 9 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Category:
Attachments
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed

Description

Hi,

We are using redmine 2.5.1 with below settings in Ubuntu 14.04 LTS

Environment:
Redmine version 2.5.1.stable
Ruby version 2.0.0-p645 (2015-04-13) [x86_64-linux-gnu]
Rails version 3.2.17
Environment production
Database adapter MySQL
SCM:
Subversion 1.8.8
Git 1.9.1
Filesystem
Redmine plugins:
AgileDwarf 0.0.3
progressive_projects_list 1.0.0
redmine_cas 1.2.1
redmine_issue_templates 0.1.0
redmine_ldap_sync 2.0.4.g0693d11a0c

Everything is working fine but our security team is rejected to expose outside (internet) becasue of there is no option for Files extensions upload restrictions.That mean, we need to allow only certain files but right now redmine is accepting all the files extensions (.exe,zip,msi,....etc). I searched in entire issues and google but no luck. Please let me know, what is the solution for this and treated this as a bug.


Files

attachment.rb.patch (1.21 KB) attachment.rb.patch actual file blocking madhusudan kh, 2015-06-09 14:51
en.yml.patch (742 Bytes) en.yml.patch message for file blocking madhusudan kh, 2015-06-09 14:51
redmine-WhitelistAndBlacklist-attachment-extensions.diff (4.08 KB) redmine-WhitelistAndBlacklist-attachment-extensions.diff Jonathan Tee, 2015-10-06 11:51
screenshot.png (59.3 KB) screenshot.png Jonathan Tee, 2015-10-06 11:52
Actions

Also available in: Atom PDF