Release 1.1.5: logo uploads are stored where they are served, and need an owner - #15
Merged
Merged
Conversation
Logos went to the default disk, which InvoiceShelf sets to the administrator's default File Disk, so wherever that is not the local storage/app the saved /storage/whitelabel/... URL pointed at nothing. They are now stored on the public disk. The upload route had no authentication and took any file type. It now requires a signed-in company owner and accepts gif, jpg and png only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reported on a non-Docker 2.x install: after uploading a logo,
/storage/whitelabel/admin_portal_logo/....pngreturned 403 and the file did not exist.storage/app, the file went somewhere/storagedoes not serve. Logos are now stored on thepublicdisk. Reproduced by pointing the default disk elsewhere: before, the URL was a 404; after, it serves the image.apimiddleware and accepted any file type. It now requiresauth:sanctumandcompany, theowner onlygate, and gif, jpg or png, like InvoiceShelf's own avatar upload.Checked on the published 2.4.5 image: uploading through the settings page shows the logo in the preview and the header. Tag
v1.1.5after merge.