sanitize only on inline content-disposition

This commit is contained in:
Andrea Spacca
2021-03-02 16:50:53 +01:00
parent 27f84e719a
commit b36711c1ea

View File

@ -1010,7 +1010,7 @@ func (s *Server) getHandler(w http.ResponseWriter, r *http.Request) {
w.Header().Set("X-Remaining-Days", remainingDays)
if strings.Contains(contentType, "html") {
if disposition == "inline" && strings.Contains(contentType, "html") {
reader = ioutil.NopCloser(
bytes.NewReader(
bluemonday.UGCPolicy().