datagovuk / dgu2

Experimental publishing prototype
MIT License
0 stars 1 forks source link

Don't trust upload headers #81

Open rossjones opened 7 years ago

rossjones commented 7 years ago

We currently use the mime-type provided by the file upload. On Windows this can be different for the same file type based on the applications installed (i.e. XLS can have one of several mime-types depending if you have office installed, and which version). It's also forgeable.