diff website/issues/extensions/local_replace.py @ 4903:48d93e98be7b

Security non-standard html content as html Attached html files are not shipped as text/html by default, unless ``allow_html_file`` is specified in the configuration. Unfortunately some browsers want to be helpful and render other non-standard content types as html. We now change this to application/octet-stream whenever 'html' is contained in the string (case insensitive). Thanks to Kay Hayen for reporting and helping debug this.
author Ralf Schlatterbeck <rsc@runtux.com>
date Fri, 04 Jul 2014 15:43:22 +0200
parents 29bc5484969a
children f87c0cca37ae
line wrap: on
line diff

Roundup Issue Tracker: http://roundup-tracker.org/