Media Library Importer
The module copies files from any folder the web user can read into the public files folder. A user with an ordinary account could make private files available for anyone to download at a predictable web address. They could not change any data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Media Library Importer to 2.1.6.
For developers: what the fix changed
The fix adds validation in `ConfigurationForm::validateForm` and `MediaLibraryImporterService::isWithinPublicFilesDirectory` to ensure that the configured import folder is located within the public files directory, preventing access to arbitrary directories.
Also in this release Added a 'process_queue_on_submit' setting, improved queue processing logic, updated documentation, and fixed PHPStan/PHPCS issues.
.gitlab-ci.yml+30 −0Agents.md+69 −0CLAUDE.md+5 −0README.md+58 −31composer.json+1 −1config/install/media_library_importer.settings.yml+1 −0config/schema/media_library_importer.schema.yml+4 −0doc/drupal_org_documentation/description.html+15 −1media_image_exif_importer/media_image_exif_importer.info.yml+0 −1media_image_exif_importer/src/Plugin/media/Source/ImageWithExif.php+1 −1media_library_importer.install+13 −11media_library_importer.links.menu.yml+12 −12