瀏覽代碼

fix: dont allow blank content of unsupported type

version-14
Sagar Vora 2 年之前
父節點
當前提交
a9fd5f5001
共有 1 個檔案被更改,包括 3 行新增1 行删除
  1. +3
    -1
      frappe/handler.py

+ 3
- 1
frappe/handler.py 查看文件

@@ -206,7 +206,9 @@ def upload_file():
frappe.local.uploaded_file = content
frappe.local.uploaded_filename = filename

if content and (frappe.session.user == "Guest" or (user and not user.has_desk_access())):
if content is not None and (
frappe.session.user == "Guest" or (user and not user.has_desk_access())
):
filetype = guess_type(filename)[0]
if filetype not in ALLOWED_MIMETYPES:
frappe.throw(_("You can only upload JPG, PNG, PDF, TXT or Microsoft documents."))


Loading…
取消
儲存