You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Yes. But I am unsure if it reveals the extension's format or it actually reads file headers(first few bytes) like file command does. Because some people try to re-upload the file by just changing the extension which is not preferable from many standpoints.
Then, probably there is no better way. Also, as files are uploaded by staffs, not normal user and uploaded files are never executed (dajngo even never executes any arbitrary python files). So extension checking is good enough. MIME checking will just allow some extra layer. But, either way sever is never effected.
Allow documents and compressed files only.
The text was updated successfully, but these errors were encountered: