X-Git-Url: https://git.mdrn.pl/redakcja.git/blobdiff_plain/05f9254a542a08ea6476c6511bf2492192d0b92e..507752b933a466dd8e962c0e34d0ec74d6de55b7:/apps/fileupload/views.py diff --git a/apps/fileupload/views.py b/apps/fileupload/views.py index 5ee12b13..2d978727 100644 --- a/apps/fileupload/views.py +++ b/apps/fileupload/views.py @@ -38,12 +38,11 @@ class JSONResponse(HttpResponse): class UploadViewMixin(object): def get_safe_path(self, filename=""): """Finds absolute filesystem path of the browsed dir of file. - + Makes sure it's inside MEDIA_ROOT. - + """ path = os.path.abspath(os.path.join(settings.MEDIA_ROOT, self.get_directory(), filename)) - # WTF how would that be possible? if not path.startswith(os.path.abspath(settings.MEDIA_ROOT)): raise Http404 if filename: @@ -137,7 +136,7 @@ class UploadView(UploadViewMixin, FormView): for chunk in f.chunks(): destination.write(chunk) data.append({ - 'name': f.name, + 'name': f.name, 'url': self.get_url(f.name), 'thumbnail_url': thumbnail(self.get_directory() + f.name), 'delete_url': "%s?file=%s" % (