Skip to content

Conversation

@i-just
Copy link
Contributor

@i-just i-just commented Nov 12, 2025

Description

We’re currently only validating allowed extensions on Elements->saveElement() in the src/validators/AssetLocationValidator.php, which happens after the file has been moved to storage/runtime/temp.

This PR ensures the extension is validated against a list of the allowed ones before the file gets moved to storage/runtime/temp.

Related issues

#18015

@i-just i-just requested a review from brandonkelly November 12, 2025 09:47
[ci skip]
@brandonkelly brandonkelly merged commit 732ea12 into 4.x Nov 13, 2025
2 checks passed
@brandonkelly brandonkelly deleted the bugfix/18015-validate-allowed-extension-early branch November 13, 2025 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants