Attachment Validation Configuration API

Last modified by Eleni Cojocariu on 2026/10/05 20:21

Reference

Six configured values decide what may be attached to a Page. AttachmentValidationConfiguration reads them from Java, $services.attachmentValidation from a wiki page. Both only read them: setting them is Restrict Attachments by Mimetype and Set the Maximum Attachment Size, enforcing them the Attachment Validation API.

The Six Values

ValueAttachmentValidationConfiguration$services.attachmentValidation
Allowed mimetypes of the current PagegetAllowedMimetypes()getAllowedMimetypes()
Allowed mimetypes of a given PagegetAllowedMimetypes(DocumentReference)getAllowedMimetypes(DocumentReference)
Blocked mimetypes of the current PagegetBlockerMimetypes()getBlockerMimetypes()
Blocked mimetypes of a given PagegetBlockerMimetypes(DocumentReference)getBlockerMimetypes(DocumentReference)
Maximum upload size of an entity, in bytesgetMaxUploadSize(EntityReference)getUploadMaxSize(EntityReference)
Maximum upload size of the current entity, in bytesgetMaxUploadSize(null)getUploadMaxSize()

The size is the one value the two names disagree on; getBlockerMimetypes is the Java name for what the administration calls a block list.

@Inject
private AttachmentValidationConfiguration configuration;

long max = this.configuration.getMaxUploadSize(documentReference);
List<String> blocked = this.configuration.getBlockerMimetypes(documentReference);
#set ($max = $services.attachmentValidation.getUploadMaxSize())
#set ($blocked = $services.attachmentValidation.getBlockerMimetypes())

Scope

The no-argument mimetype forms answer for the current Page, taking the nearest configuration level that is not empty. The DocumentReference overloads answer for the Page given, by swapping the context document around that lookup, so they see that Page's configuration rather than the request's. An unresolvable reference answers an empty list.

The size is not resolved that way: it is the upload_maxsize preference, inherited the way a Page preference is, and an unresolvable entity answers its default.

When the Implementation Is Absent

xwiki-platform-attachment-validation-default holds the only implementation of the role and need not be installed. The script service therefore looks it up at each call and, on failure, answers an empty list, or 0 for a size: a script cannot tell "nothing configured" from "nothing installed", but it never sees an error. Java code injecting the role gets no such cushion, and the chain itself falls back its own way.

Related

Get Connected