This release contains security fixes. Upgrading is recommended for every 5.x install, including installs already on 5.5.1. Details will be published in security advisories.
If you're upgrading from 5.5.0 or earlier, also follow the 5.5.1 upgrade step and run php artisan curator:repair-extensions --dry-run, then php artisan curator:repair-extensions.
Changed
- Upload types are detected from the file's contents.
- Curator detects an upload's type from the file's own bytes, instead of the type reported for the upload.
- The accepted-types check and the stored extension both use the detected type.
- Scriptable types need an exact match.
- HTML, XML, JavaScript and similar types, and
application/octet-stream, are accepted only when listed exactly. - A wildcard such as
text/*orapplication/*no longer matches them.
- HTML, XML, JavaScript and similar types, and
- SVGs are sanitized before they're written to disk.
- An SVG that can't be sanitized is rejected, and nothing is stored.
- Testing your app's uploads:
UploadedFile::fake()->create()files are zero-filled, so they're now detected asapplication/octet-streamand rejected.- Use real file contents in upload tests. See Testing uploads.
Fixed
- Legacy Office files:
.doc,.xlsand.pptfiles keep their type. - CSV and calendar files:
.csvand.icsfiles detected as plain text are typedtext/csvandtext/calendar. - Replacements:
curator:repair-extensionsonly deletes an original after its replacement has been written. - Custom messages: a custom
mimetypesvalidation message is used again.
Added in #755.
What's Changed
Full Changelog: v5.5.1...v5.5.2