diff options
author | Go MAEDA <maeda@farend.jp> | 2023-09-18 02:26:15 +0000 |
---|---|---|
committer | Go MAEDA <maeda@farend.jp> | 2023-09-18 02:26:15 +0000 |
commit | 15d0ea8c596f306131de2bd7edd1ae28ff122103 (patch) | |
tree | 2c05c745896aacd9a9fb36601e9502eb25985a47 | |
parent | 001e48a1510fc227753e636a9f8dfbedf48a9130 (diff) | |
download | redmine-15d0ea8c596f306131de2bd7edd1ae28ff122103.tar.gz redmine-15d0ea8c596f306131de2bd7edd1ae28ff122103.zip |
Merged r22294 and r22295 from trunk to 5.0-stable (#38417).
git-svn-id: https://svn.redmine.org/redmine/branches/5.0-stable@22296 e93f8b46-1217-0410-a6f0-8f06a7374b81
-rw-r--r-- | app/controllers/attachments_controller.rb | 7 | ||||
-rw-r--r-- | app/controllers/repositories_controller.rb | 5 |
2 files changed, 11 insertions, 1 deletions
diff --git a/app/controllers/attachments_controller.rb b/app/controllers/attachments_controller.rb index c991fce06..e3d3c5bd4 100644 --- a/app/controllers/attachments_controller.rb +++ b/app/controllers/attachments_controller.rb @@ -89,7 +89,7 @@ class AttachmentsController < ApplicationController tbnail, :filename => filename_for_content_disposition(@attachment.filename), :type => detect_content_type(@attachment, true), - :disposition => 'inline') + :disposition => 'attachment') end else # No thumbnail for the attachment or thumbnail could not be created @@ -321,4 +321,9 @@ class AttachmentsController < ApplicationController request.raw_post end end + + def send_file(path, options={}) + headers['content-security-policy'] = "default-src 'none'; style-src 'unsafe-inline'; sandbox" + super + end end diff --git a/app/controllers/repositories_controller.rb b/app/controllers/repositories_controller.rb index 0e83bfa1e..147a60c12 100644 --- a/app/controllers/repositories_controller.rb +++ b/app/controllers/repositories_controller.rb @@ -433,6 +433,11 @@ class RepositoriesController < ApplicationController end end + def send_file(path, options={}) + headers['content-security-policy'] = "default-src 'none'; style-src 'unsafe-inline'; sandbox" + super + end + def valid_name?(rev) return true if rev.nil? return true if REV_PARAM_RE.match?(rev) |