mirror of
https://github.com/discourse/discourse.git
synced 2025-05-22 06:34:57 +08:00
SECURITY: force IM decoder based on file extension
This commit is contained in:
@ -93,7 +93,7 @@ describe OptimizedImage do
|
||||
}.not_to raise_error
|
||||
end
|
||||
|
||||
it "raises nothing on paths" do
|
||||
it "raises InvalidAccess error on paths" do
|
||||
expect {
|
||||
OptimizedImage.ensure_safe_paths!("/a.png", "/b.png", "c.png")
|
||||
}.to raise_error(Discourse::InvalidAccess)
|
||||
|
Reference in New Issue
Block a user