Fix CVE-2023-31047

This commit is contained in:
2024-06-22 21:16:42 +02:00
parent e681c17a0f
commit e1bf7caa9a
3 changed files with 30 additions and 6 deletions

View File

@ -30,7 +30,7 @@ from ajax_select import make_ajax_field
from ajax_select.fields import AutoCompleteSelectMultipleField
from core.views import CanViewMixin, CanEditMixin
from core.views.files import send_file, FileView
from core.views.files import send_file, FileView, MultipleImageField
from core.models import SithFile, User, Notification, RealGroup
from sas.models import Picture, Album, PeoplePictureRelation
@ -40,8 +40,7 @@ class SASForm(forms.Form):
album_name = forms.CharField(
label=_("Add a new album"), max_length=30, required=False
)
images = forms.ImageField(
widget=forms.ClearableFileInput(attrs={"multiple": True}),
images = MultipleImageField(
label=_("Upload images"),
required=False,
)