An uploaded file downloads as <title>.pdf whatever it was #193
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#193
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Found while fixing #191, on the line next to it.
UploadDownloadViewhands every uploaded file over aswhatever the file is. The upload field accepts
pdf, doc, docx, odt, rtf, txt, png, jpg, jpeg(UploadedDocument.file's validator), so a person who uploadsreference.docxunderthe title Reference downloads
Reference.pdf-- a Word document with a PDF extension,which their PDF viewer then refuses to open.
Why it matters
the operating system what the bytes are. A
.docxnamed.pdffails to open on everydesktop until the person guesses to rename it.
RenderedDocumentDownloadViewdoes the same thing and isright to: a snapshot is always a PDF Postulo drew.
Doing it
Take the suffix from the stored name --
Path(document.file.name).suffix-- and use thetitle for the stem, which keeps the readable name people already get. The stored name's
suffix is the upload's own, since
upload_to_documentskeeps the file name.Worth a test that uploads a
.txtand checks theContent-Dispositionfilename, next totest_an_uploaded_file_is_delivered_only_to_its_owner, which checks the header starts withattachment;and nothing about the name.