diff --git a/classquiz/routers/editor.py b/classquiz/routers/editor.py index 6dd460e..06df97b 100644 --- a/classquiz/routers/editor.py +++ b/classquiz/routers/editor.py @@ -97,8 +97,9 @@ async def upload_image(edit_id: str, pow_data: str, file: UploadFile = File()): raise HTTPException(status_code=401, detail="Edit ID not found!") if uploaded_images != 0 and not check_hashcash(pow_data, pow_data_server, "17"): raise HTTPException(status_code=401, detail="Edit ID not found!") - file_bytes = await file.read() + if len(file_bytes) < 2000: + raise HTTPException(status_code=400, detail="File too large") pm_data = puremagic.magic_string(file_bytes)[0] if pm_data.extension not in allowed_image_extensions: raise HTTPException(status_code=400, detail="Image-type now allowed!") diff --git a/frontend/src/lib/editor/uploader.svelte b/frontend/src/lib/editor/uploader.svelte index 2d88b99..9d61f81 100644 --- a/frontend/src/lib/editor/uploader.svelte +++ b/frontend/src/lib/editor/uploader.svelte @@ -39,7 +39,14 @@ .use(XHRUpload, { endpoint: `/api/v1/editor/image?edit_id=${edit_id}&pow_data=${pow_data}` }); - const props = { inline: true }; + const props = { + inline: true, + restrictions: { + maxFileSize: 2000, + maxNumberOfFiles: 1, + allowedFileTypes: ['.gif', '.jpg', '.jpeg', '.png', '.svg', '.webp'] + } + }; let image_id; uppy.on('upload-success', (file, response) => { image_id = response.body.id;