Opened 3 years ago

Closed 2 months ago

Last modified 8 weeks ago

#21548 closed New feature (fixed)

Add the ability to limit file extensions for ImageField and FileField

Reported by: timo Owned by: berkerpeksag
Component: Forms Version: master
Severity: Normal Keywords:
Cc: anubhav9042@…, berker.peksag@… Triage Stage: Ready for checkin
Has patch: yes Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no


ImageField/FileField could have an optional extension whitelist. This could default to being empty for both fields to be totally backwards compatible, or could have sensible defaults for the ImageField based on the file types supported by PIL/low. The documentation should warn that you should not rely on file extensions to determine the actual content type of files.

There are probably some existing implementations we could borrow from, for example:

Change History (11)

comment:1 Changed 2 years ago by jfilipe

  • Owner changed from nobody to jfilipe
  • Status changed from new to assigned

comment:2 Changed 2 years ago by jfilipe

I have a work in progress PR here:

Wanted to get some feedback on the approach before I added some docs.

comment:3 Changed 2 years ago by jfilipe

  • Has patch set

comment:4 Changed 2 years ago by timo

  • Needs documentation set
  • Patch needs improvement set

Hi, I left a comment for improvement on the PR, although it's better to open a PR against Django itself instead of your fork.

comment:5 Changed 2 years ago by anubhav9042

The patch looks good but the validator must be like others as Tim suggested on your PR.
Also adding it to ImageField by default sounds good. I hope we can fix #18543 with it.

comment:6 Changed 2 years ago by anubhav9042

  • Cc anubhav9042@… added

comment:7 Changed 5 months ago by berkerpeksag

  • Cc berker.peksag@… added
  • Needs documentation unset
  • Owner changed from jfilipe to berkerpeksag
  • Patch needs improvement unset

Pull request:


  • Added two validators: FileExtensionValidator and validate_image_file (this one uses FileExtensionValidator with default values from PIL.Image.EXTENSION).
  • Added validate_image_file to ImageField as a default validator.
  • Added tests for FileExtensionValidator, model and form validations.
  • Added documentation and release notes. I probably need to add some note for ImageField docs too.

comment:8 Changed 5 months ago by timgraham

  • Patch needs improvement set

Left some comments for improvement.

comment:9 Changed 2 months ago by timgraham

  • Patch needs improvement unset
  • Triage Stage changed from Accepted to Ready for checkin

comment:10 Changed 2 months ago by Tim Graham <timograham@…>

  • Resolution set to fixed
  • Status changed from assigned to closed

In 12b4280:

Fixed #21548 -- Added FileExtensionValidator and validate_image_file_extension.

comment:11 Changed 8 weeks ago by Baptiste Mispelon <bmispelon@…>

In a9215b7c:

Refs #21548 -- Skipped tests that rely on pillow when it's not installed

Note: See TracTickets for help on using tickets.
Back to Top