diff options
author | Lukas Reschke <lukas@owncloud.com> | 2015-06-22 15:30:27 +0200 |
---|---|---|
committer | Lukas Reschke <lukas@owncloud.com> | 2015-06-22 15:30:27 +0200 |
commit | 3d2ac6dbb62252d251d2c10907f28eb3b8458836 (patch) | |
tree | d741f5edb1fe7826d8f342436666da5f27c13ba7 /apps | |
parent | a88b370dc84c4dfdcab7a128900829fbe8204ca7 (diff) | |
download | nextcloud-server-3d2ac6dbb62252d251d2c10907f28eb3b8458836.tar.gz nextcloud-server-3d2ac6dbb62252d251d2c10907f28eb3b8458836.zip |
Use trusted mimetype
We shall not use untrusted mimetypes in this context
Diffstat (limited to 'apps')
-rw-r--r-- | apps/files_versions/download.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/apps/files_versions/download.php b/apps/files_versions/download.php index 72018ca68b9..3cc324c2306 100644 --- a/apps/files_versions/download.php +++ b/apps/files_versions/download.php @@ -34,7 +34,7 @@ $versionName = '/'.$uid.'/files_versions/'.$filename.'.v'.$revision; $view = new OC\Files\View('/'); -$ftype = $view->getMimeType('/'.$uid.'/files/'.$filename); +$ftype = \OC_Helper::getSecureMimeType($view->getMimeType('/'.$uid.'/files/'.$filename)); header('Content-Type:'.$ftype); OCP\Response::setContentDispositionHeader(basename($filename), 'attachment'); |