# Restrict uploads

**URL:** https://meta.discourse.org/t/restrict-uploads/112688
**Category:** Theme component
**Created:** [March 27, 2019, 11:03am UTC](https://meta.discourse.org/t/restrict-uploads/112688 "2019-03-27T11:03:40Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [March 27, 2019, 11:03am UTC](https://meta.discourse.org/t/restrict-uploads/112688/1 "2019-03-27T11:03:40Z")

</div>

This is a very small theme component that will remove the upload button from the composer toolbar and disable drag-and-drop uploading for users that are under a specified trust level.

### Illustration

 ![unrestricted](https://global.discourse-cdn.com/meta/original/3X/f/a/fab88bc4ff1f11a741407ad4d0f9a88dc6aaa316.png)

 ![restricted](https://global.discourse-cdn.com/meta/original/3X/7/a/7a741edb4abdd6cd334f712fd40c44bfb5ae0e2c.png)

### Settings

 ![setting](https://global.discourse-cdn.com/meta/original/3X/4/2/4292fad5fcaed15bd1dbbf30da0ccd5db0bcaa6b.png)

| | | |
| --- | --- | --- |
| 🛠 | **Repository** | [github.com/tshenry/discourse-restrict-uploads](https://github.com/tshenry/discourse-restrict-uploads) |
| 📖 | **New to Discourse Themes?** | [Beginner’s guide to using Discourse Themes](https://meta.discourse.org/t/beginners-guide-to-using-discourse-themes/91966) |

Install this theme component

---

<div class="post-metadata">

### Author: ![YTPMania\_Forums](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ytpmania_forums/32/134014_2.png) [@YTPMania\_Forums](https://meta.discourse.org/u/YTPMania_Forums)
#### Post date: [March 30, 2019, 5:43pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/2 "2019-03-30T17:43:28Z")

</div>

My forum is pushing 1.1GB in uploaded media. We’re growing in a way I wasn’t super prepared for and have been trying to coerce users to use places like imgur instead. This really, really helps!

---

<div class="post-metadata">

### Author: ![PoojaPatel](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@PoojaPatel](https://meta.discourse.org/u/PoojaPatel)
#### Post date: [October 2, 2019, 10:33am UTC](https://meta.discourse.org/t/restrict-uploads/112688/3 "2019-10-02T10:33:41Z")

</div>

I have try this components but its not working.

Can @tshenry help me?

This are the screen shot of my installation. I want to restrict user who have trust level 2 or below

 ![Restrict%20Uploads](https://global.discourse-cdn.com/meta/original/3X/0/0/0017375b766dbebcd9d09b7cba9975afdef66b3c.png)

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [October 2, 2019, 3:22pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/4 "2019-10-02T15:22:40Z")

</div>

Hi there 👋

I just checked and it appears to be working correctly. Can you make sure you have added the Restrict Uploads component to your main theme? You will also need to hard-refresh the page for the component to take effect. Oh, and make sure the account you are using for testing is not a staff user.

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [November 14, 2019, 10:19pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/5 "2019-11-14T22:19:01Z")

</div>

> ⚠ A note to anyone using this component - there is an update to the component that requires you to be running the latest tests-passed version of Discourse. If your Discourse site is not up to date, DO NOT update the component as it will reference core code that you do not have yet which will break the composer functionality of your site.

---

<div class="post-metadata">

### Author: ![Iceman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iceman/32/181309_2.png) [@Iceman](https://meta.discourse.org/u/Iceman)
#### Post date: [August 24, 2020, 3:58pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/6 "2020-08-24T15:58:30Z")

</div>

Hi,

Just posting to note this:

> [@Unable to see the Text Box on the Composer after update to 2.6.0.beta2](https://meta.discourse.org/t/unable-to-see-the-text-box-on-the-composer-after-update-to-2-6-0-beta2/161726/4):
>
> New post just to inform that, if I remove the Mod Status to a Mod User (that has this bug), after refreshing the page they will be able to write without issue, the box will appear. Which confirms that the issue only happens to Mods and Admins. But I’ve been combing down my plugins, also tried the ?safe\_mode=only\_official mode and it doesn’t change, only happens to Mods/Admins. Now, this is the fun part, while I was writing the lines above it came to me that “the only difference is with Admin/…

I _think_ it is broken (for Admins and Mods) on 2.6.0.beta2, but I’m unable to get more confirmation besides my own experience.

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [August 25, 2020, 1:49am UTC](https://meta.discourse.org/t/restrict-uploads/112688/7 "2020-08-25T01:49:34Z")

</div>

Thanks so much for the report @Iceman! I just pushed a fix that should get things back on track 🙂  
Let me know if there are any issues after you update the component.

[https://github.com/tshenry/discourse-restrict-uploads/commit/b52fb9def1a00773ca4462e2d15444eea1ff934c](https://github.com/tshenry/discourse-restrict-uploads/commit/b52fb9def1a00773ca4462e2d15444eea1ff934c)

---

<div class="post-metadata">

### Author: ![Iceman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iceman/32/181309_2.png) [@Iceman](https://meta.discourse.org/u/Iceman)
#### Post date: [August 25, 2020, 2:36am UTC](https://meta.discourse.org/t/restrict-uploads/112688/8 "2020-08-25T02:36:29Z")

</div>

Just tested and works just as before, that is, like a charm!

Thank you very much!

---

<div class="post-metadata">

### Author: ![Jennifer\_Abrams](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jennifer_abrams/32/150388_2.png) [@Jennifer\_Abrams](https://meta.discourse.org/u/Jennifer_Abrams)
#### Post date: [March 26, 2021, 3:52pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/9 "2021-03-26T15:52:16Z")

</div>

doesn’t restrict avi uploads

would be nice if it did

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [March 26, 2021, 7:30pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/10 "2021-03-26T19:30:13Z")

</div>

Can you elaborate a little more?

I just tried uploading an AVI from a trust level lower than the one defined in the `restrict to trust level` theme setting and it prevented the upload as expected.

If you would like to prevent non-staff users from uploading AVI files specifically, you should ensure the AVI extension isn’t added to `authorized extensions`. You can add the extension to  
`authorized extensions for staff` if you want staff to be able to upload AVIs.

---

<div class="post-metadata">

### Author: ![yhmtsai](https://avatars.discourse-cdn.com/v4/letter/y/47e85d/32.png) [@yhmtsai](https://meta.discourse.org/u/yhmtsai)
#### Post date: [September 6, 2021, 9:41pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/11 "2021-09-06T21:41:32Z")

</div>

it is really cool.  
Could it separate the restriction between post and personal message?  
for example, only allow staff upload image in personal message but tl2 can upload images in normal post

---

<div class="post-metadata">

### Author: ![Iceman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iceman/32/181309_2.png) [@Iceman](https://meta.discourse.org/u/Iceman)
#### Post date: [September 10, 2021, 1:06pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/12 "2021-09-10T13:06:22Z")

</div>

Hey, just want to point out that this “breaks” with Discourse Latest ( 2.8.0.beta6 ([0d809197aa](https://github.com/discourse/discourse/commits/0d809197aaa567629ebbfe1201948e91f38cea3a)) ).

`TypeError: null is not an object (evaluating ´this.mobileUploadButton.addEventListener´)`

#### Details:

- Started to happen after a Rebuild (and therefore, update to latest).

- This only happens on Mobile.

- Doesn’t happen on all browsers, neither on all devices (could be a cache thing? idk). But once it happens there is no way to “fix it” from a user’s perspective.

- The behavior is weird because it “changes” how the buttons behave. The “discard” button (trash can) and Preview buttons reload the page. The “Discourse Gifs Theme Component” Button just expands the composer.

- I thought it was some compatibility issue with the “Discourse Gifs” Theme Component but if I disable that one the issue persists.

I can provide more details if necessary. I tried removing as much as possible but it seems that he problem only stops happening after disabling this Theme Component.

* * *

btw, just want to use the opportunity and point out what a great Theme Component this is and how much I do think that it should be a core feature 💌

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [September 10, 2021, 8:03pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/13 "2021-09-10T20:03:59Z")

</div>

> [@Iceman](#):
>
> Hey, just want to point out that this “breaks” with Discourse Latest

Thanks for reporting this! There has been some recent work on our core upload system and there appears to be a little bug. I’m actually able to reproduce the error even without the component under the right circumstances. I’ll pass this by the engineer that’s been focusing on uploads to see if we can get this fixed up!

> [@yhmtsai](#):
>
> Could it separate the restriction between post and personal message?

That sounds like a reasonable feature request! I’ll see what I can do.

---

<div class="post-metadata">

### Author: ![martin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/martin/32/491371_2.png) [@martin](https://meta.discourse.org/u/martin)
#### Post date: [September 12, 2021, 11:51pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/15 "2021-09-12T23:51:52Z")

</div>

Hi @Iceman. Thanks for the report, the issue is fixed by [FIX: Do not error mobile upload button if !allowUpload by martin-brennan · Pull Request #14317 · discourse/discourse · GitHub](https://github.com/discourse/discourse/pull/14317) which is in tests-passed now.

---

<div class="post-metadata">

### Author: ![Crius](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/crius/32/317214_2.png) [@Crius](https://meta.discourse.org/u/Crius)
#### Post date: [January 8, 2024, 4:15pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/16 "2024-01-08T16:15:10Z")

</div>

I am noticing this message in console.

> [THEME 6 ‘Restrict Uploads’] To prevent errors in tests, add a `pluginId` key to your `modifyClass` call. This will ensure the modification is only applied once.

Just thought to raise it as it may become a potential issue once the [recent changes](https://meta.discourse.org/t/preparing-for-discourses-upgrade-to-ember-5/287211) go live for everyone.

---

<div class="post-metadata">

### Author: ![Arkshine](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/arkshine/32/298682_2.png) [@Arkshine](https://meta.discourse.org/u/Arkshine)
#### Post date: [January 8, 2024, 4:34pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/17 "2024-01-08T16:34:44Z")

</div>

Thanks for the report. I made a PR 👍

[https://github.com/tshenry/discourse-restrict-uploads/pull/1](https://github.com/tshenry/discourse-restrict-uploads/pull/1)

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [January 8, 2024, 8:44pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/18 "2024-01-08T20:44:27Z")

</div>

🚀 Merged, thanks!

---

<div class="post-metadata">

### Author: ![hipp0](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hipp0/32/537433_2.png) [@hipp0](https://meta.discourse.org/u/hipp0)
#### Post date: [January 23, 2026, 8:57pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/22 "2026-01-23T20:57:44Z")

</div>

Place holder text is different for users under that aren’t in the allowed Trust Level Group

composer.reply\_placeholder\_no\_images

Added for Trust Level 0,1,2, I have Restrict uploads set to Trust Level 3.

> [@Place holder text in new topic or reply is wrong (Composer.reply\_placeholder\_no\_images)](https://meta.discourse.org/t/place-holder-text-in-new-topic-or-reply-is-wrong-composer-reply-placeholder-no-images/394225/2):
>
> Does it also happen is [safe mode](https://meta.discourse.org/t/53504?silent=true)?

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [January 23, 2026, 11:35pm UTC](https://meta.discourse.org/t/restrict-uploads/112688/23 "2026-01-23T23:35:40Z")

</div>

I think I was able to fix the placeholder so it works with RTE and Markdown editor

 ![restricted uploads](https://global.discourse-cdn.com/meta/original/4X/3/7/d/37d1799ccfcaab80e8f0ddddf92de58a6e5b8df4.png)  
[https://github.com/tshenry/discourse-restrict-uploads/pull/3](https://github.com/tshenry/discourse-restrict-uploads/pull/3)

---

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [January 24, 2026, 12:13am UTC](https://meta.discourse.org/t/restrict-uploads/112688/24 "2026-01-24T00:13:30Z")

</div>

The fix has been merged 🚀 Thanks again, @Moin! If you end up working on the additional modernization, ping me when it’s ready and I’ll work on getting it merged.

[Next page](https://meta.discourse.org/t/restrict-uploads/112688.md?page=2)
