Restrict Attachments by Mimetype for a Whole Farm
Last modified by Eleni Cojocariu on 2026/09/30 17:41
Steps
Set the mimetype lists that every wiki of a farm falls back to, one of the limits Attachments introduces, by editing xwiki.properties.
- Open the xwiki.properties file of your installation.
/etc/xwiki/xwiki.properties <xwiki web application>/WEB-INF/xwiki.properties - Uncomment attachment.upload.allowList and list the mimetypes you accept, or attachment.upload.blockList and the ones you refuse, separated by commas.
attachment.upload.allowList=text/plain,image/* - Restart XWiki.
- Attach a file of a refused type to a Page of any wiki: the upload is turned down, and the notice quotes the list XWiki read from the file.

FAQ
Does an edited list take effect without restarting XWiki?
No. XWiki reads xwiki.properties once, as it starts, so an edited list applies from the next restart.
Which file is read when there are two?
/etc/xwiki/xwiki.properties, and the copy under WEB-INF is then left unread. XWiki takes one file or the other, never both.
Does a wiki of the farm fall back to the main wiki's lists?
No. Each wiki reads the lists of its own administration, and where it sets none it falls back to the file rather than to the main wiki.
Can one wiki accept a mimetype the file refuses?
Yes, by giving that wiki a "Blocked Mimetypes" list that does not name that mimetype. Clearing the field instead hands the wiki back to the file, since an empty list counts as none at all.