Sfoglia il codice sorgente

feat: replace file content type to avoid load script in svg. (#16454)

Signed-off-by: -LAN- <laipz8200@outlook.com>
-LAN- 1 mese fa
parent
commit
ac910ed200
1 ha cambiato i file con 1 aggiunte e 0 eliminazioni
  1. 1 0
      api/controllers/files/image_preview.py

+ 1 - 0
api/controllers/files/image_preview.py

@@ -75,6 +75,7 @@ class FilePreviewApi(Resource):
         if args["as_attachment"]:
             encoded_filename = quote(upload_file.name)
             response.headers["Content-Disposition"] = f"attachment; filename*=UTF-8''{encoded_filename}"
+        response.headers["Content-Type"] = "application/octet-stream"
 
         return response