Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
C
canifa_note
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Vũ Hoàng Anh
canifa_note
Commits
46d5307d
Commit
46d5307d
authored
May 21, 2025
by
Steven
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
fix: prevent XSS for specific content types
parent
c2528c57
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
6 additions
and
0 deletions
+6
-0
resource_service.go
server/router/api/v1/resource_service.go
+6
-0
No files found.
server/router/api/v1/resource_service.go
View file @
46d5307d
...
...
@@ -188,6 +188,12 @@ func (s *APIV1Service) GetResourceBinary(ctx context.Context, request *v1pb.GetR
if
strings
.
HasPrefix
(
contentType
,
"text/"
)
{
contentType
+=
"; charset=utf-8"
}
// Prevent XSS attacks by serving potentially unsafe files with a content type that prevents script execution.
if
strings
.
EqualFold
(
contentType
,
"image/svg+xml"
)
||
strings
.
EqualFold
(
contentType
,
"text/html"
)
||
strings
.
EqualFold
(
contentType
,
"application/xhtml+xml"
)
{
contentType
=
"application/octet-stream"
}
return
&
httpbody
.
HttpBody
{
ContentType
:
contentType
,
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment