Avatars with .svg extension dont loaded in 2.2.0.beta3 +64 version


(Julian) #1

I am trying from a while to upload an svg image for my avatar but it’s impossible.

When a update to 2.2.0.beta3 +64 version, all user having avatar image with svg extension was replaced by default image
image


(Jeff Atwood) #2

I am not sure we even want to support this cc @tgxworld ?


(Sam Saffron) #3

Yeah we should block svg avatars


(Alan Tan) #5

I had a look here and confirmed this is a regression.

There was a change made to use IM_DECODERS to verify if an image can be optimized but we actually don’t need to optimize SVGs at all. What used to happen in the previous versions is that SVG “optimized images” are basically a copy of the original image.

I think we should just avoid creating optimized images for SVG altogether and retain support.


(Stephen) #7

Do we do anything to strip script tags from within SVG? Are they handled as <img> or <object>?


(Julian) #10

There are a real problem to handle svg images as avatars?

Until now, the avatar images in svg have worked perfectly. I don’t understand why the headache


(Jeff Atwood) #11

Too much of a security and performance and complexity risk. Nobody needs a SVG avatar.


(Sam Saffron) #12

We had a bunch of internal regressions around svg support, very few noticed it cause very few bother whitelisting svgs.

This is now fixed:


(Stephen) #13

So SVG now works, except as avatars?


(Sam Saffron) #14

If SVG is the poison you are into drinking and you enable it, it works for avatars and inside posts.

It was pretty broken previously.


(Stephen) #15

You both agreed above that they were a Very Bad Idea only three weeks ago, out of curiosity what changed?


(Sam Saffron) #16

It was easier just to fix the underlying bug. It is more work to block it and add a test for blocking it, the risk of allowing svg avatars is not too high.

I will probably revisit this and block it unconditionally though cause there are just too many edge cases which make me uneasy.

In particular you could set an svg avatar to say a 500k image and that is the thumbnail and everything, that would be brutal, fixing that edge case is not worth the effort.


(Sam Saffron) #17

This topic was automatically closed after 3 days. New replies are no longer allowed.