Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ENH] Upload a zip file of assets and Oqtane to add them to the filemanager #4207

Open
leigh-pointer opened this issue Apr 30, 2024 · 2 comments

Comments

@leigh-pointer
Copy link
Contributor

leigh-pointer commented Apr 30, 2024

Oqtane Info

Version - 5.1.1
Render Mode - Static
Interactivity - Server
Database - SQL Server

Describe the enhancement

Would be nice to be able to upload a zip file of assests and Oqtuane to add them to the filemanager. The path inside the zip file would dictate the folder stucture on the server.

Anything else?

@leigh-pointer leigh-pointer changed the title [ENH] [ENH] Upload a zip file of assests and Oqtuane to add them to the filemanager. Apr 30, 2024
@sbwalker sbwalker changed the title [ENH] Upload a zip file of assests and Oqtuane to add them to the filemanager. [ENH] Upload a zip file of assests and Oqtane to add them to the filemanager. Apr 30, 2024
@sbwalker sbwalker changed the title [ENH] Upload a zip file of assests and Oqtane to add them to the filemanager. [ENH] Upload a zip file of assets and Oqtane to add them to the filemanager. Apr 30, 2024
@sbwalker
Copy link
Member

sbwalker commented Apr 30, 2024

I am guessing any new folders created would inherit the security permissions of the folder where the ZIP file was uploaded? ZIP file uploads are famous for security vulnerabilities (ie. https://security.snyk.io/vuln/SNYK-DOTNET-SHARPZIPLIB-2385941) so this enhancement would need a lot of testing.

@sbwalker sbwalker changed the title [ENH] Upload a zip file of assets and Oqtane to add them to the filemanager. [ENH] Upload a zip file of assets and Oqtane to add them to the filemanager Apr 30, 2024
@leigh-pointer
Copy link
Contributor Author

Picking the permission from the file manager sounds right also the extensions would need to be checked which should help reduce the vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants