fix: add isascii() check in safe_name to prevent non-ASCII chars in PDF Content-Disposition header
CI / lint (push) Successful in 14s
CI / security (push) Successful in 8s
CI / test (push) Successful in 26s
CI / build (push) Successful in 4s

This commit is contained in:
2026-06-05 08:24:32 -04:00
parent 4a6e907f3f
commit fff658d551
+2 -2
View File
@@ -1348,7 +1348,7 @@ async def api_file_pdf(vault_name: str, path: str = Query(..., description="Rela
title = post.metadata.get("title", file_path.stem)
pdf_html = build_pdf_html(html, str(title))
pdf_bytes = generate_pdf(pdf_html, str(title))
safe_name = "".join(c for c in str(title) if c.isalnum() or c in " _-.").strip() or "document"
safe_name = "".join(c for c in str(title) if c.isascii() and (c.isalnum() or c in " _-.")).strip() or "document"
return Response(content=pdf_bytes, media_type="application/pdf", headers={"Content-Disposition": f'attachment; filename="{safe_name}.pdf"'})
@@ -3811,7 +3811,7 @@ async def public_share_pdf_download(token: str):
title = post.metadata.get("title", file_path.stem)
pdf_html = build_pdf_html(html, str(title))
pdf_bytes = generate_pdf(pdf_html, str(title))
safe_name = "".join(c for c in str(title) if c.isalnum() or c in " _-.").strip() or "document"
safe_name = "".join(c for c in str(title) if c.isascii() and (c.isalnum() or c in " _-.")).strip() or "document"
return Response(content=pdf_bytes, media_type="application/pdf", headers={"Content-Disposition": f'attachment; filename="{safe_name}.pdf"'})