PU 501 (Synergy): Whitelist mechanism introduced for attachment upload
Previously, the web user controls such as ImageField,
FileFields, FilesField, and PictureControl were used to select and upload or
attach the files to Exact Synergy Enterprise. Depending on the controls and
usage, there were different types of validations including file types, size,
and others. However, there was no central mechanism for the administrator to
define which file type was allowed.
In
this product update, we have introduced the file attachment and upload
whitelist. Once the whitelist is configured at Modules > System > Setup
> Settings - General > All, only the file types that are included in the
whitelist are accepted. The administrators can specify the file extensions that
Exact Synergy Enterprise will accept. By default, this feature is not enabled
but it can be enabled and configured by the administrator. To do this, see How-to:
Configuring the whitelist for file attachments and uploads.
Once the feature is enabled, only the files with
the extensions listed on the whitelist
are filtered. If you select a file with an extension that is not in the
whitelist, Exact Synergy Enterprise will reject the file and you will be asked
to contact the administrator. You will see the following error message:
This feature is available for the following:
- Word merge
- Configurator
- Workspace
- Account
- HTML input control
Note: This
feature does not affect Exact Connectivity Layer (ECL).
Main Category: |
Attachments & notes |
Document Type: |
Release notes detail |
Category: |
|
Security level: |
All - 0 |
Sub category: |
|
Document ID: |
30.956.221 |
Assortment: |
Exact Synergy Enterprise
|
Date: |
04-01-2024 |
Release: |
|
Attachment: |
|
Disclaimer |