From 185aa5d49c4781262e967081e2e280f29a94de72 Mon Sep 17 00:00:00 2001 From: Tom J Nowell Date: Sun, 20 Sep 2026 18:06:28 +0100 Subject: [PATCH] Cache the contents of an uploaded SVG icon uploaded_icon_markup() read the file on every render. Where uploads are in remote storage such as S3 Uploads, that is a network request per icon button per uncached page view. The entry is keyed on the attachment's modified time and has no expiry, so there is no TTL to pick and updating the attachment retires it. Only the file contents are cached, so one entry serves every size. --- SECURITY.md | 6 +++++ inc/render.php | 65 +++++++++++++++++++++++++++++++++++++------------- 2 files changed, 55 insertions(+), 16 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 69a671f..f61862c 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -16,6 +16,12 @@ disk, and writes its contents into the page as inline SVG. The file is not sanitised and is not put through the Icons API allowlist, because keeping strokes, groups and gradients is the whole point of the upload escape hatch. +The file's contents are held in the object cache, keyed on the attachment ID +and its modified time. Sanitising a file that is already uploaded only reaches +the page once the attachment is updated or the cache is flushed. The mime type +is checked before the cache is read, so a deleted attachment stops rendering +straight away. + Inline SVG is part of the document. A `