uploads-v0.52.0
·
85 commits
to main
since this release
Minor Changes
- 286cafc:
putandattachaccept non-media files: PDF, zip, gzip, MOV, and text (plain, markdown, CSV, JSON, logs). They upload as-is, skip image optimization, and appear in the managed comment as links. Requires the matching platform release. - 99340ec:
putandattachaccept SVG and XML (image/svg+xml,application/xml,text/xml) on a storage lane once its public host is verified to serve them behind a sandboxing Content-Security-Policy. An unverified lane keeps 415ing these types. The managed comment embeds SVG as<img>. Requires the matching platform release.
Patch Changes
- 3bdadcf: The active-content host probe now retries a failed
REGISTRYKV write once before giving up, so a stale prior-dayok: truerecord can't survive a one-off KV hiccup and keep the SVG/XML sandboxing gate open. - e3b1f85: Sharpen the server-side reputation pre-filter for gated SVG/XML uploads (
containsActiveMarkup): event-handler attribute matching no longer false-positives on ordinary attributes likeonline=/once=, and entity-encoded evasions (javascript:, SMIL<set attributeName="onclick">) are now rejected. The actual security control remains the sandboxing CSP on the serving lane; this filter is defense in depth. - 15d34d6:
put --helpnow says uploads are public and to scrub secrets out of logs, JSON, and other text before uploading. - cada618: Read width/height for SVG uploads from the root
<svg>tag'swidth/heightattributes (orviewBoxas a fallback), soimage.width/image.heightserver metadata — and the managed GitHub comment's sizing — now cover SVGs the same as other image types.