An uploaded file downloads as <title>.pdf whatever it was #193

Closed
opened 2026-09-12 14:43:24 +00:00 by tiagoagueda · 0 comments
Owner

Observation

Found while fixing #191, on the line next to it.

UploadDownloadView hands every uploaded file over as

download_name=f"{document.title}.pdf"

whatever the file is. The upload field accepts pdf, doc, docx, odt, rtf, txt, png, jpg, jpeg (UploadedDocument.file's validator), so a person who uploads reference.docx under
the title Reference downloads Reference.pdf -- a Word document with a PDF extension,
which their PDF viewer then refuses to open.

Why it matters

  • It is a wrong answer, not a cosmetic one. The whole point of the extension is telling
    the operating system what the bytes are. A .docx named .pdf fails to open on every
    desktop until the person guesses to rename it.
  • Only uploads are affected. RenderedDocumentDownloadView does the same thing and is
    right to: a snapshot is always a PDF Postulo drew.

Doing it

Take the suffix from the stored name -- Path(document.file.name).suffix -- and use the
title for the stem, which keeps the readable name people already get. The stored name's
suffix is the upload's own, since upload_to_documents keeps the file name.

Worth a test that uploads a .txt and checks the Content-Disposition filename, next to
test_an_uploaded_file_is_delivered_only_to_its_owner, which checks the header starts with
attachment; and nothing about the name.

## Observation Found while fixing #191, on the line next to it. `UploadDownloadView` hands every uploaded file over as download_name=f"{document.title}.pdf" whatever the file is. The upload field accepts `pdf, doc, docx, odt, rtf, txt, png, jpg, jpeg` (`UploadedDocument.file`'s validator), so a person who uploads `reference.docx` under the title *Reference* downloads `Reference.pdf` -- a Word document with a PDF extension, which their PDF viewer then refuses to open. ## Why it matters - **It is a wrong answer, not a cosmetic one.** The whole point of the extension is telling the operating system what the bytes are. A `.docx` named `.pdf` fails to open on every desktop until the person guesses to rename it. - **Only uploads are affected.** `RenderedDocumentDownloadView` does the same thing and is right to: a snapshot is always a PDF Postulo drew. ## Doing it Take the suffix from the stored name -- `Path(document.file.name).suffix` -- and use the title for the stem, which keeps the readable name people already get. The stored name's suffix is the upload's own, since `upload_to_documents` keeps the file name. Worth a test that uploads a `.txt` and checks the `Content-Disposition` filename, next to `test_an_uploaded_file_is_delivered_only_to_its_owner`, which checks the header starts with `attachment;` and nothing about the name.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo#193
No description provided.