fix(branding): accept SVG favicons

The favicon upload allowed only PNG/ICO, so an SVG favicon was rejected.
Accept image/svg+xml (.svg) too - DynamicFavicon already emits the right
MIME type and served SVGs are CSP-locked (render-only) by secureStatic.
Update the EN/DE help text accordingly.
This commit is contained in:
Luca
2026-06-03 16:34:38 +02:00
parent 307b84fe05
commit 12591556a0
3 changed files with 12 additions and 7 deletions
+10 -5
View File
@@ -76,7 +76,8 @@ const faviconUpload = multer({
limits: { fileSize: 2 * 1024 * 1024 }, // 2MB — roomy enough for a 512×512+ square PNG
fileFilter: (req, file, cb) => {
const allowedMimeTypes = ['image/png', 'image/x-icon', 'image/vnd.microsoft.icon'];
const name = file.originalname.toLowerCase();
// For ICO files, we can't use the standard validateFileType
if (file.mimetype === 'image/png') {
if (validateFileType(file.originalname, file.mimetype, ['image/png'])) {
@@ -84,12 +85,16 @@ const faviconUpload = multer({
} else {
cb(new Error('Invalid PNG file'));
}
} else if (allowedMimeTypes.includes(file.mimetype) &&
(file.originalname.toLowerCase().endsWith('.ico') ||
file.originalname.toLowerCase().endsWith('.png'))) {
} else if (file.mimetype === 'image/svg+xml' && name.endsWith('.svg')) {
// SVG favicons are supported by modern browsers and are crisp at any
// size. Served SVGs are CSP-locked (no script execution) by the
// secureStatic middleware, so an admin-uploaded SVG is render-only.
cb(null, true);
} else if (allowedMimeTypes.includes(file.mimetype) &&
(name.endsWith('.ico') || name.endsWith('.png'))) {
cb(null, true);
} else {
cb(new Error('Favicon must be PNG or ICO format'));
cb(new Error('Favicon must be PNG, ICO, or SVG format'));
}
}
});