From a346912030012dc1451249373ff7ef1a61016517 Mon Sep 17 00:00:00 2001 From: Claire Date: Sun, 25 Apr 2021 12:02:41 +0200 Subject: [PATCH] Add environment variables to control custom emoji size limits Fixes #1524 --- .env.production.sample | 7 +++++++ app/models/custom_emoji.rb | 7 +++++-- 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/.env.production.sample b/.env.production.sample index 12ca64a066..65f3f9d1f3 100644 --- a/.env.production.sample +++ b/.env.production.sample @@ -269,3 +269,10 @@ MAX_POLL_OPTION_CHARS=100 # Maximum search results to display # Only relevant when elasticsearch is installed # MAX_SEARCH_RESULTS=20 + +# Maximum custom emoji file sizes +# If undefined or smaller than MAX_EMOJI_SIZE, the value +# of MAX_EMOJI_SIZE will be used for MAX_REMOTE_EMOJI_SIZE +# Units are in bytes +MAX_EMOJI_SIZE=51200 +MAX_REMOTE_EMOJI_SIZE=204800 diff --git a/app/models/custom_emoji.rb b/app/models/custom_emoji.rb index 7cb03b8199..f143579322 100644 --- a/app/models/custom_emoji.rb +++ b/app/models/custom_emoji.rb @@ -21,7 +21,8 @@ # class CustomEmoji < ApplicationRecord - LIMIT = 50.kilobytes + LOCAL_LIMIT = (ENV['MAX_EMOJI_SIZE'] || 50.kilobytes).to_i + LIMIT = [LOCAL_LIMIT, (ENV['MAX_REMOTE_EMOJI_SIZE'] || 200.kilobytes).to_i].max SHORTCODE_RE_FRAGMENT = '[a-zA-Z0-9_]{2,}' @@ -38,7 +39,9 @@ class CustomEmoji < ApplicationRecord before_validation :downcase_domain - validates_attachment :image, content_type: { content_type: IMAGE_MIME_TYPES }, presence: true, size: { less_than: LIMIT } + validates_attachment :image, content_type: { content_type: IMAGE_MIME_TYPES }, presence: true + validates_attachment_size :image, less_than: LIMIT, unless: :local? + validates_attachment_size :image, less_than: LOCAL_LIMIT, if: :local? validates :shortcode, uniqueness: { scope: :domain }, format: { with: /\A#{SHORTCODE_RE_FRAGMENT}\z/ }, length: { minimum: 2 } scope :local, -> { where(domain: nil) }