From 2680d9fb23449192bdbd96baeac5c0aceaf63191 Mon Sep 17 00:00:00 2001 From: kaalibro Date: Mon, 20 Jul 2026 04:49:00 +0500 Subject: [PATCH] fix(user_manager): allow inline rendering for user.css Update FileResponse headers to permit inline loading specifically for the user.css file. Other files will continue to be served as attachments to maintain security against XSS. --- app/user_manager.py | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/app/user_manager.py b/app/user_manager.py index de261ad39..5514e9a1c 100644 --- a/app/user_manager.py +++ b/app/user_manager.py @@ -343,13 +343,22 @@ class UserManager(): # XSS). Content-Disposition: attachment is the load-bearing guard; # the content-type override and nosniff are defence in depth. content_type = mimetypes.guess_type(path)[0] or 'application/octet-stream' - if folder_paths.is_dangerous_content_type(content_type): - content_type = 'application/octet-stream' + + # Strict check: allow inline loading only for the exact user.css file + is_user_css = os.path.basename(path) == "user.css" + + if is_user_css: + content_type = "text/css" + disposition = "inline" + else: + if folder_paths.is_dangerous_content_type(content_type): + content_type = 'application/octet-stream' + disposition = "attachment" return web.FileResponse(path, headers={ "Content-Type": content_type, "X-Content-Type-Options": "nosniff", - "Content-Disposition": "attachment", + "Content-Disposition": disposition, }) @routes.post("/userdata/{file}")