Opened 2 years ago

Last modified 3 weeks ago

#21548 assigned New feature

Add the ability to limit file extensions for ImageField and FileField

Reported by: timo Owned by: berkerpeksag
Component: Forms Version: master
Severity: Normal Keywords:
Cc: anubhav9042@…, berker.peksag@… Triage Stage: Accepted
Has patch: yes Needs documentation: no
Needs tests: no Patch needs improvement: yes
Easy pickings: no UI/UX: no

Description

ImageField/FileField could have an optional extension whitelist. This could default to being empty for both fields to be totally backwards compatible, or could have sensible defaults for the ImageField based on the file types supported by PIL/low. The documentation should warn that you should not rely on file extensions to determine the actual content type of files.

There are probably some existing implementations we could borrow from, for example:

https://djangosnippets.org/snippets/977/

Change History (8)

comment:1 Changed 2 years ago by jfilipe

  • Owner changed from nobody to jfilipe
  • Status changed from new to assigned

comment:2 Changed 2 years ago by jfilipe

I have a work in progress PR here: https://github.com/jfilipe/django/pull/2

Wanted to get some feedback on the approach before I added some docs.

comment:3 Changed 2 years ago by jfilipe

  • Has patch set

comment:4 Changed 2 years ago by timo

  • Needs documentation set
  • Patch needs improvement set

Hi, I left a comment for improvement on the PR, although it's better to open a PR against Django itself instead of your fork.

comment:5 Changed 23 months ago by anubhav9042

The patch looks good but the validator must be like others as Tim suggested on your PR.
Also adding it to ImageField by default sounds good. I hope we can fix #18543 with it.

comment:6 Changed 23 months ago by anubhav9042

  • Cc anubhav9042@… added

comment:7 Changed 5 weeks ago by berkerpeksag

  • Cc berker.peksag@… added
  • Needs documentation unset
  • Owner changed from jfilipe to berkerpeksag
  • Patch needs improvement unset

Pull request: https://github.com/django/django/pull/6343

Changes:

  • Added two validators: FileExtensionValidator and validate_image_file (this one uses FileExtensionValidator with default values from PIL.Image.EXTENSION).
  • Added validate_image_file to ImageField as a default validator.
  • Added tests for FileExtensionValidator, model and form validations.
  • Added documentation and release notes. I probably need to add some note for ImageField docs too.

comment:8 Changed 3 weeks ago by timgraham

  • Patch needs improvement set

Left some comments for improvement.

Note: See TracTickets for help on using tickets.
Back to Top