Uploaded image for project: 'Confluence'
  1. Confluence
  2. CONF-6931

Restrict Attachments Based on File type

    Details

    • Type: Suggestion
    • Status: Resolved
    • Resolution: Won't Fix
    • Affects Version/s: 2.4, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.5, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7, 2.5.8, 2.6.0, 2.6.1, 2.6.2, 2.7, 2.7.1, 2.7.2, 2.7.3, 2.8, 2.8.1, 2.8.2, 2.9, 2.9.1, 2.9.2
    • Fix Version/s: None
    • Component/s: None
    • Last commented by user?:
      true

      Description

      Is it possible to restrict the type of the uploaded file, for example to allow an upload of files of the type *.jpg. *.gif, *.png only ?

        Attachments

          Issue Links

            Activity

            Hide
            johannes.rudolf Johannes Rudolf added a comment - - edited

            Additionally this is an security risk and it's the vendor's responsibility to take care about the product. Since users are able to upload *.svg files or any other file type that is easy to infiltrate, these files could contain malware. No need to explain the consequences...!

            Show
            johannes.rudolf Johannes Rudolf added a comment - - edited Additionally this is an security risk and it's the vendor's responsibility to take care about the product. Since users are able to upload *.svg files or any other file type that is easy to infiltrate, these files could contain malware. No need to explain the consequences...!
            Hide
            pranjal.shukla Pranjal Shukla added a comment -

            This should be fixed by Atlassian as this has been identifying as major security risk in my organization too. This is delaying the deployment of the tool.

            Show
            pranjal.shukla Pranjal Shukla added a comment - This should be fixed by Atlassian as this has been identifying as major security risk in my organization too. This is delaying the deployment of the tool.
            Hide
            pranjal.shukla Pranjal Shukla added a comment -

            Also, the reason this feature becomes absolutely imperative is that it questions the existence of Confluence. If we allow big sized word/excel files, people would upload the files rather than creating content in Confluence. If this continues, no organization can stop Confluence from becoming a dumping ground of files.

            Moreover many organizations restrict sharing of binary files (Executable) over mails and files above certain size. Due to unavailability of this feature, i have seen teams using File Lists to share binary files and EXE's with each other which they are not allowed to do over mails.

            Show
            pranjal.shukla Pranjal Shukla added a comment - Also, the reason this feature becomes absolutely imperative is that it questions the existence of Confluence. If we allow big sized word/excel files, people would upload the files rather than creating content in Confluence. If this continues, no organization can stop Confluence from becoming a dumping ground of files. Moreover many organizations restrict sharing of binary files (Executable) over mails and files above certain size. Due to unavailability of this feature, i have seen teams using File Lists to share binary files and EXE's with each other which they are not allowed to do over mails.
            Hide
            pranjal.shukla Pranjal Shukla added a comment -

            Participants,
            We are asking Atlassian to fix this but the votes tell different story all together. We know Atlassian is serious about implementing an issue based on votes so please vote for it and ask others to vote too. I feel this is a serious issue and needs attention from Atlassian.

            @matt@atlassian.com, This should be fixed, any reasons why you guys are not paying heed to it??

            Show
            pranjal.shukla Pranjal Shukla added a comment - Participants, We are asking Atlassian to fix this but the votes tell different story all together. We know Atlassian is serious about implementing an issue based on votes so please vote for it and ask others to vote too. I feel this is a serious issue and needs attention from Atlassian. @matt@atlassian.com, This should be fixed, any reasons why you guys are not paying heed to it??
            Hide
            ashpakov Andrei added a comment -

            just when the hope has been awakened - it is back to 'won't fix'.
            sad

            Show
            ashpakov Andrei added a comment - just when the hope has been awakened - it is back to 'won't fix'. sad

              People

              • Votes:
                16 Vote for this issue
                Watchers:
                30 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Last commented:
                  38 weeks ago