<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block mimetype for all but 1 site? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284721#M237851</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'll leave it to you and Jay to discuss.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't think its appropriate to enable .svg for one site only since that could be vulnerable to XSS.&amp;nbsp;&amp;nbsp;&amp;nbsp; Perhaps the .svg could be filtered or transformed?&amp;nbsp;&amp;nbsp; I think that's the way to go.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Apr 2014 15:26:42 GMT</pubDate>
    <dc:creator>mrogers</dc:creator>
    <dc:date>2014-04-09T15:26:42Z</dc:date>
    <item>
      <title>Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284717#M237847</link>
      <description>Hello,I'm looking to ask if anyone would know if it's possible to block a mimetype on a site-by-site basis. Recently there was an update which blocks .svg mimetypes from opening natively (ie. View in browser), because of XSS concerns, requiring employees to save locally instead, which is undesired.</description>
      <pubDate>Tue, 08 Apr 2014 11:50:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284717#M237847</guid>
      <dc:creator>avatar47</dc:creator>
      <dc:date>2014-04-08T11:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284718#M237848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You could have a policy that throws an exception on addition of the banned mimetype.&amp;nbsp;&amp;nbsp;&amp;nbsp; Not elegant - but it will work.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 10:37:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284718#M237848</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2014-04-09T10:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284719#M237849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'll discuss your proposed solution with our infrastructure team, thanks mrogers! &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:26:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284719#M237849</guid>
      <dc:creator>avatar47</dc:creator>
      <dc:date>2014-04-09T12:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284720#M237850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi mrojers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I represent the infrastructure team Alex was referring to.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;First, I'd like to provide you some context. Alex was referring to ticket MNT-8453: "View in browser" function in Share was disabled for SVG files in Alfresco Enterprise 4.1.5. Alex asks if it is possible to re-enable this function per-site basis.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, if I got your idea correct, you suggest to disable &amp;lt;em&amp;gt;adding&amp;lt;/em&amp;gt; SVG documents (depending on how we implement this, this can be done per-site basis). But that's not what we would like to achieve. We still want that users are able to upload SVG files, and we want that "View in browser" function in Share is still disabled for SVG files by default - but if some Share site manager insists, this function can be re-enabled for this specific site.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please correct me if I got your idea wrong.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Huge thanks and warm regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Anton&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For reference: I am conducting a conversation on this topic on support ticket 00153174 with Jay Sinha.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 13:34:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284720#M237850</guid>
      <dc:creator>anton_udintsev</dc:creator>
      <dc:date>2014-04-09T13:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284721#M237851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'll leave it to you and Jay to discuss.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't think its appropriate to enable .svg for one site only since that could be vulnerable to XSS.&amp;nbsp;&amp;nbsp;&amp;nbsp; Perhaps the .svg could be filtered or transformed?&amp;nbsp;&amp;nbsp; I think that's the way to go.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 15:26:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284721#M237851</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2014-04-09T15:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block mimetype for all but 1 site?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284722#M237852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Apologies for poking my nose in here again, but could you elaborate on the 'filtered' option? Transforming .svgs would mean losing a considerable amount of native functionality, it is not really an option for us. If by filtering you mean that they are pre-scanned for suspicious activity, that could be an option.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Secondly, I was informed that XSS attacks are, for larger companies, somewhat rare (or even impossible), as usually there are numerous hardware/software combinations which block XSS activity from occuring at all in any given intranet. For example, F5 Networks sells a 'Application Management Systems' (AMS) which scans at Layer 7 for XSS activity, and then blocks it. I was hoping our company was already in possession of such equipment perhaps (I assure you I am not a salesman for F5, but for anyone's interest perhaps -&amp;gt; &lt;/SPAN&gt;&lt;A href="https://f5.com/glossary/cross-site-scripting" rel="nofollow noopener noreferrer"&gt;https://f5.com/glossary/cross-site-scripting&lt;/A&gt;&lt;SPAN&gt; ).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thirdly, if .svg 'view in browser' were enabled for only 1 site, and that site were fully audited and controlled tightly, then *surely* that must significantly be a lower risk, no? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 16:01:20 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/block-mimetype-for-all-but-1-site/m-p/284722#M237852</guid>
      <dc:creator>avatar47</dc:creator>
      <dc:date>2014-04-09T16:01:20Z</dc:date>
    </item>
  </channel>
</rss>

