sanitize only on inline content-disposition
This commit is contained in:
@ -1010,7 +1010,7 @@ func (s *Server) getHandler(w http.ResponseWriter, r *http.Request) {
|
|||||||
w.Header().Set("X-Remaining-Days", remainingDays)
|
w.Header().Set("X-Remaining-Days", remainingDays)
|
||||||
|
|
||||||
|
|
||||||
if strings.Contains(contentType, "html") {
|
if disposition == "inline" && strings.Contains(contentType, "html") {
|
||||||
reader = ioutil.NopCloser(
|
reader = ioutil.NopCloser(
|
||||||
bytes.NewReader(
|
bytes.NewReader(
|
||||||
bluemonday.UGCPolicy().
|
bluemonday.UGCPolicy().
|
||||||
|
Reference in New Issue
Block a user