<!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>attachment</title> <meta name="viewport" content="width=device-width, initial-scale=1" /> <link rel="stylesheet" href="../style.css" type="text/css" /> <link rel="stylesheet" href="../local.css" type="text/css" /> </head> <body> <div class="page"> <div class="pageheader"> <div class="header"> <span> <span class="parentlinks"> <a href="../index.html">ikiwiki</a>/ <a href="../plugins.html">plugins</a>/ </span> <span class="title"> attachment </span> </span> </div> </div> <div id="pagebody"> <div id="content" role="main"> <p><span class="infobox"> Plugin: attachment<br /> Author: <span class="createlink">Joey</span><br /> Included in ikiwiki: yes<br /> Enabled by default: no<br /> Included in <a href="./goodstuff.html">goodstuff</a>: no<br /> Currently enabled: no<br /> </span></p> <p>This plugin allows files to be uploaded to the wiki over the web.</p> <p>For each page <code>foo</code>, files in the subdirectory <code>foo/</code> are treated as attachments of that page. Attachments can be uploaded and managed as part of the interface for editing a page.</p> <p>Warning: Do not enable this plugin on publically editable wikis, unless you take care to lock down the types and sizes of files that can be uploaded. Bear in mind that if you let anyone upload a particular kind of file ("*.mp3" files, say), then someone can abuse your wiki in at least three ways:</p> <ol> <li>By uploading many mp3 files, wasting your disk space.</li> <li>By uploading mp3 files that attempt to exploit security holes in web browsers or other players.</li> <li>By uploading files that claim to be mp3 files, but are really some other kind of file. Some web browsers may display a <code>foo.mp3</code> that contains html as a web page; including running any malicious javascript embedded in that page.</li> </ol> <p>If you enable this plugin, be sure to lock it down, via the <code>allowed_attachments</code> setup file option. This is a special <a href="../ikiwiki/pagespec/attachment.html">enhanced PageSpec</a> using tests provided by the <a href="./filecheck.html">filecheck</a> plugin. That plugin will be automatically enabled when this plugin is enabled.</p> </div> </div> <div id="footer" class="pagefooter" role="contentinfo"> <div id="pageinfo"> <div class="tags"> Tags: <a href="./type/web.html" rel="tag">type/web</a> </div> <div id="backlinks"> Links: <a href="./filecheck.html">filecheck</a> <a href="../news/ikiwiki_version_3.0.html">news/ikiwiki version 3.0</a> <a href="../rcs.html">rcs</a> <a href="../rcs/git.html">rcs/git</a> <a href="../roadmap.html">roadmap</a> <a href="../tips/untrusted_git_push.html">tips/untrusted git push</a> <a href="./transient.html">transient</a> </div> <div class="pagedate"> Last edited <span class="date">Tue Feb 26 23:01:54 2019</span> <!-- Created <span class="date">Tue Feb 26 23:01:54 2019</span> --> </div> </div> <!-- from ikiwiki --> </div> </div> </body> </html>