0
0
Fork 0

Rename media to avoid exposing filename (fixes #207)

This commit is contained in:
Andrea Faulds 2016-11-23 21:00:00 +00:00
parent 3373ae02de
commit 7161f91313
2 changed files with 16 additions and 2 deletions

View file

@ -20,7 +20,18 @@ class Settings::ProfilesController < ApplicationController
private
def account_params
params.require(:account).permit(:display_name, :note, :avatar, :header, :silenced)
p = params.require(:account).permit(:display_name, :note, :avatar, :header, :silenced)
if p[:avatar]
avatar = p[:avatar]
# Change so Paperclip won't expose the actual filename
avatar.original_filename = "media" + File.extname(avatar.original_filename)
end
if p[:header]
header = p[:header]
# Change so Paperclip won't expose the actual filename
header.original_filename = "media" + File.extname(header.original_filename)
end
p
end
def set_account