diff options
author | blizzz <blizzz@arthur-schiwon.de> | 2021-06-02 21:15:25 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2021-06-02 21:15:25 +0200 |
commit | 0bbb195af19ddfc1a4fb15623f973c0c47deb16a (patch) | |
tree | 016d3d6de2f72b35b0557c8b0bfd39282c979fe2 /lib | |
parent | 949102c03171c3e3a0d48d590b5a810a42ab6160 (diff) | |
parent | 377514aad14ad3c5297daf14b848ef470ae56f22 (diff) | |
download | nextcloud-server-0bbb195af19ddfc1a4fb15623f973c0c47deb16a.tar.gz nextcloud-server-0bbb195af19ddfc1a4fb15623f973c0c47deb16a.zip |
Merge pull request #27354 from nextcloud/escape-download-response
Escape filename in Content-Disposition
Diffstat (limited to 'lib')
-rw-r--r-- | lib/public/AppFramework/Http/DownloadResponse.php | 8 |
1 files changed, 2 insertions, 6 deletions
diff --git a/lib/public/AppFramework/Http/DownloadResponse.php b/lib/public/AppFramework/Http/DownloadResponse.php index 78381f0f08f..a7516fc6b85 100644 --- a/lib/public/AppFramework/Http/DownloadResponse.php +++ b/lib/public/AppFramework/Http/DownloadResponse.php @@ -30,20 +30,16 @@ namespace OCP\AppFramework\Http; * @since 7.0.0 */ class DownloadResponse extends Response { - private $filename; - private $contentType; - /** * Creates a response that prompts the user to download the file * @param string $filename the name that the downloaded file should have * @param string $contentType the mimetype that the downloaded file should have * @since 7.0.0 */ - public function __construct($filename, $contentType) { + public function __construct(string $filename, string $contentType) { parent::__construct(); - $this->filename = $filename; - $this->contentType = $contentType; + $filename = strtr($filename, ['"' => '\\"', '\\' => '\\\\']); $this->addHeader('Content-Disposition', 'attachment; filename="' . $filename . '"'); $this->addHeader('Content-Type', $contentType); |