Skip to content

Security: Blog: Create post attachments only together with the post - #9200

Merged
AngelFQC merged 4 commits into
chamilo:masterfrom
AngelFQC:security/blog-attachments-on-post-create
Oct 9, 2026
Merged

AngelFQC merged 4 commits into
chamilo:masterfrom
AngelFQC:security/blog-attachments-on-post-create

Conversation

@AngelFQC

@AngelFQC AngelFQC commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Attachments can now only be added when a blog post is created: POST /api/c_blog_posts takes a multipart request (title, fullText, blog, files[], comments[]) and creates the post and its files in one transaction. The standalone POST /api/c_blog_attachments/upload is removed, so files can no longer be added to an existing post. This matches 1.11.x, where attachments are only set by the author in the post creation form. The blog UI (createPostWithFiles) now sends a single request; the edit dialog already had no file picker.

Note: POST /api/c_blog_posts no longer accepts a JSON body; the blog UI was its only client.

Refs GHSA-958p-rxgr-q423

@AngelFQC
AngelFQC merged commit c79fb42 into chamilo:master Oct 9, 2026
3 of 6 checks passed
@AngelFQC
AngelFQC deleted the security/blog-attachments-on-post-create branch October 9, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant