# Default File Upload Types

**URL:** https://meta.discourse.org/t/default-file-upload-types/28359
**Category:** Feature
**Created:** [May 5, 2015, 6:40pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359 "2015-05-05T18:40:48Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![strager](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@strager](https://meta.discourse.org/u/strager)
#### Post date: [May 5, 2015, 6:40pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/1 "2015-05-05T18:40:48Z")

</div>

So it came to my attention today that by default (or at least here on Meta) there are a few major file types missing from the upload option. It would be great if the default (and Meta) allowed users to upload file types such as Word Docs, Excel Sheets, PDFs, etc. as these are the most likely files users would want to upload.

Below are the options on our own instance which I am fairly confident have not been changed - this is extremely restrictive.

![](https://global.discourse-cdn.com/meta/original/3X/4/5/45714f09c71af9174ef040e0bc99d6afcc442d12.png)

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [May 6, 2015, 1:44am UTC](https://meta.discourse.org/t/default-file-upload-types/28359/2 "2015-05-06T01:44:10Z")

</div>

Those would be potential security exploits if enabled globally. I suggest just enabling what you need on your instance as you see fit.

---

<div class="post-metadata">

### Author: ![Bill\_S](https://avatars.discourse-cdn.com/v4/letter/b/22d042/32.png) [@Bill\_S](https://meta.discourse.org/u/Bill_S)
#### Post date: [May 7, 2015, 5:01pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/3 "2015-05-07T17:01:06Z")

</div>

How much of a security risk do you think adding pdf extensions would be?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [May 7, 2015, 5:46pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/4 "2015-05-07T17:46:39Z")

</div>

High. Do users regularly need to upload PDFs?

---

<div class="post-metadata">

### Author: ![Bill\_S](https://avatars.discourse-cdn.com/v4/letter/b/22d042/32.png) [@Bill\_S](https://meta.discourse.org/u/Bill_S)
#### Post date: [May 7, 2015, 5:59pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/5 "2015-05-07T17:59:25Z")

</div>

No, I don’t allow file uploads either. I was just checking best practices.

---

<div class="post-metadata">

### Author: ![strager](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@strager](https://meta.discourse.org/u/strager)
#### Post date: [May 12, 2015, 10:22pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/6 "2015-05-12T22:22:38Z")

</div>

@codinghorror - would the plugin at [https://meta.discourse.org/t/google-docs-onebox-for-discourse/26247/29](https://meta.discourse.org/t/google-docs-onebox-for-discourse/26247/29) have the same security implications since the files are stored on Google Drive? I wouldn’t think so, but figured I’d check with you before I brought the idea to Bill…

---

<div class="post-metadata">

### Author: ![DeanMarkTaylor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/deanmarktaylor/32/102462_2.png) [@DeanMarkTaylor](https://meta.discourse.org/u/DeanMarkTaylor)
#### Post date: [May 12, 2015, 10:26pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/7 "2015-05-12T22:26:48Z")

</div>

Google Drive has a virus scanning policy which **reduces** the risks:

> **[Storage and upload limits for Google Workspace  |  Drive & Docs  |  Google...](https://knowledge.workspace.google.com/admin/drive/storage-and-upload-limits-for-google-workspace?hl=en&visit_id=639159038321515986-2547955851&rd=1)**

> Virus scanning: Google Drive scans a file for viruses before the file is downloaded or shared. If a virus is detected, users can’t share the file with others, send the infected file via email, or convert it to a Google Doc, Sheet, or Slide, and they’ll receive a warning if they attempt these operations. The owner can download the virus-infected file, but only after acknowledging the risk of doing so.

> Only files smaller than 25 MB can be scanned for viruses. For larger files, a warning is displayed saying that the file can’t be scanned.

---

<div class="post-metadata">

### Author: ![Andro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/andro/32/173721_2.png) [@Andro](https://meta.discourse.org/u/Andro)
#### Post date: [December 12, 2020, 10:25pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/8 "2020-12-12T22:25:36Z")

</div>

I know this is five years later, but my question is I believe still pertinent. What is the security risk and issue with allowing PDF uploads?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [December 13, 2020, 11:06pm UTC](https://meta.discourse.org/t/default-file-upload-types/28359/9 "2020-12-13T23:06:18Z")

</div>

It is usually reasonably safe on modern PDF clients:

> <https://security.stackexchange.com/questions/72037/what-are-the-security-risks-associated-with-pdf-files>

Firefox these days has a native renderer which reduces risks further.

That said, I would say the vast majority of Discourse forums do not need this enabled so I think the default we have is just fine.
