Limit avatar image size

fixes #4041
This commit is contained in:
Frédéric Guillot 2019-02-01 12:12:36 -08:00
parent 6c421da47a
commit fa08493348
1 changed files with 6 additions and 0 deletions

View File

@ -59,6 +59,12 @@ class AvatarFileController extends BaseController
{
$user_id = $this->request->getIntegerParam('user_id');
$size = $this->request->getStringParam('size', 48);
if ($size > 100) {
$this->response->status(400);
return;
}
$filename = $this->avatarFileModel->getFilename($user_id);
$etag = md5($filename.$size);