Disable libvips unfuzzed operations (#226)

and add test coverage for (un)supported file types.

The avatar and logo variants move into the models and return nil for content
types that are no longer variable, so the controllers fall back to the initials
avatar and stock logo icon instead of raising `ActiveStorage::InvariableError`.
This commit is contained in:
Mike Dalessio
2026-07-28 11:57:57 -04:00
committed by GitHub
parent 69e8cd7885
commit b065b40a34
11 changed files with 198 additions and 14 deletions
+9 -1
View File
@@ -1,6 +1,14 @@
class Account < ApplicationRecord
include Joinable
has_one_attached :logo
has_one_attached :logo do |attachable|
attachable.variant :large, resize_to_limit: [ 512, 512 ], format: :png
attachable.variant :small, resize_to_limit: [ 192, 192 ], format: :png
end
has_json :settings, restrict_room_creation_to_administrators: false
def logo_variant(size)
logo.variant(size).processed if logo.variable?
end
end
+7 -1
View File
@@ -2,7 +2,9 @@ module User::Avatar
extend ActiveSupport::Concern
included do
has_one_attached :avatar
has_one_attached :avatar do |attachable|
attachable.variant :square, resize_to_limit: [ 512, 512 ], format: :webp
end
end
class_methods do
@@ -14,4 +16,8 @@ module User::Avatar
def avatar_token
signed_id(purpose: :avatar)
end
def avatar_variant
avatar.variant(:square).processed if avatar.variable?
end
end