parent
f73e8cde88
commit
c65f9f169c
|
|
@ -343,13 +343,22 @@ class UserManager():
|
|||
# XSS). Content-Disposition: attachment is the load-bearing guard;
|
||||
# the content-type override and nosniff are defence in depth.
|
||||
content_type = mimetypes.guess_type(path)[0] or 'application/octet-stream'
|
||||
if folder_paths.is_dangerous_content_type(content_type):
|
||||
content_type = 'application/octet-stream'
|
||||
|
||||
user_root = self.get_request_user_filepath(request, None, create_dir=False)
|
||||
is_user_css = path == os.path.abspath(os.path.join(user_root, "user.css"))
|
||||
|
||||
if is_user_css:
|
||||
content_type = "text/css"
|
||||
disposition = "inline"
|
||||
else:
|
||||
if folder_paths.is_dangerous_content_type(content_type):
|
||||
content_type = 'application/octet-stream'
|
||||
disposition = "attachment"
|
||||
|
||||
return web.FileResponse(path, headers={
|
||||
"Content-Type": content_type,
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
"Content-Disposition": "attachment",
|
||||
"Content-Disposition": disposition,
|
||||
})
|
||||
|
||||
@routes.post("/userdata/{file}")
|
||||
|
|
|
|||
Loading…
Reference in New Issue