Fix ImageMagick errors when trying to identify image dimensions#10343
Merged
alecslupu merged 2 commits intodecidim:developfrom Mar 14, 2023
Merged
Fix ImageMagick errors when trying to identify image dimensions#10343alecslupu merged 2 commits intodecidim:developfrom
alecslupu merged 2 commits intodecidim:developfrom
Conversation
Contributor
|
indeed, when using: |
alecslupu
approved these changes
Mar 14, 2023
This was referenced Mar 15, 2023
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
…ent-blocks * feature/redesign: (97 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
…le-card * feature/redesign: (94 commits) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) Fix dynamic upload file field required indicator + make option naming consistent (#10497) Standardize the format of the words "should not" (#10515) Standardize the format of the words "were not" (#10516) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
* feature/redesign: (99 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Redesign: layout item (#10376) Feature/redesign order filter (#10563) Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
* feature/redesign: (94 commits) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) Fix dynamic upload file field required indicator + make option naming consistent (#10497) Standardize the format of the words "should not" (#10515) Standardize the format of the words "were not" (#10516) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
* feature/redesign: (98 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Redesign: layout item (#10376) Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
* feature/redesign: (97 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
…-l-g * feature/redesign: (99 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Redesign: layout item (#10376) Feature/redesign order filter (#10563) Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
…content-blocks * feature/redesign: (99 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Redesign: layout item (#10376) Feature/redesign order filter (#10563) Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
…s-l-g * feature/redesign: (97 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 23, 2023
* feature/redesign: (97 commits) Feature/redesign accountability versions (#10517) Redesign: add image to blog item (#10458) Redesign: search results (#10380) Fix test Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) Remove the deprecated `optional` option from the file upload modal (#10542) Standardize the format of the words "does not" (#10505) Standardize the format of the words "was not" (#10514) Add Procfile support (#10519) Standardize the format of the words "do not" (#10513) Change the `optional` option to `required` at participatory texts (#10498) Fix destroying scope types that have been associated with processes (#10496) ...
entantoencuanto
added a commit
that referenced
this pull request
Mar 24, 2023
…dcrumb * feature/redesign: (282 commits) include a clause to change a data-attr on the fly Update tests Restore specs Feature/redesign accountability versions (#10517) set different modals foreach comment Redesign: add image to blog item (#10458) unify report button for futher uses Redesign: search results (#10380) Fix test Redesign: layout item (#10376) Feature/redesign order filter (#10563) Finalize word standardization (#10557) Fix iframes stripped from admin entered proposals, meetings and debates (#10466) Fix ImageMagick errors when trying to identify image dimensions (#10343) Add required to proposal limit field in Proposal component (#10525) Standardize the format of the words "is not" (#10511) Standardize the format of the words "has not" (#10510) Standardize the format of the words "will not" (#10509) Make buttons respect the organizations' primary color (#10526) Fix flaky spec for questionnaire templates (#10544) ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

🎩 What? Why?
Newer ImageMagick versions have changed the default security policy to allow maximum image sizes of 8192 in either dimension as per:
https://imagemagick.org/script/security-policy.php
The Decidim default dev images ship an image named
malicious.jpgoriginating from #334 which is testing that the Decidim is not vulnerable against the pixel flood attack:https://hackerone.com/reports/390
The test itself is valid but we should handle the ImageMagick errors properly and rescue from them. I am adding a new error to be shown to the user in these cased:
File cannot be processed. This makes it easier for admins to try to identify the issue why users might not be able to upload certain images than just showingFile resolution is too largein these cases.This should also help us towards making Decidim work out of the box with Ubuntu 22.04 and other distros alike.
📌 Related Issues
Link your PR to an issue
ubuntu-latest#10143Testing
malicious.jpgshipped with thedecidim-devgem as the default user's avatar image