Page 1 of 1

Media allowed in Knowledge Base

Posted: 19 Mar 2015 10:50
by tatewise
Jane, it seems that the file types alowed in Knowledge Base Media uploads are more restricted than in Forum Attachments, e.g. TXT and LOG are forbidden.
However, ZIP is OK, so anything can get uploaded indirectly, and therefore there is little reason to ban anything.

Now that pushfile> downloads are allowed in KB, most filetypes should be allowed similar to the Forum Usage Guide (4252):
Many file types are allowed including all FH custom data files and gedcom files (ged),
image files such as GIF, JPEG, JPG, PNG, TGA, TIF, TIFF,
plain text files such as XML, TXT, LOG, JS, CSV, CPP,
document files such as DOC, DOCX, ODG, ODP, ODS, ODT, PDF, PPT, PPTX, RTF, XLS, XLSX
and a few more besides.

Re: Media allowed in Knowledge Base

Posted: 19 Mar 2015 11:45
by Jane
The main reason for the limitations are to do with cross site scripting, a zip file can not easily have code directly executed on a server, but allowing the upload of say an HTML or js file on Dokuwiki could expose the site to then having that script / page executed directly.

I have added

txt !text/plain
log !text/plain
csv !application/msexcel

docx !application/msword
xlsx !application/msexcel
pptx !application/mspowerpoint

To the allowed extension list on the Knowledge base.