Closed MartijnR closed 6 years ago
the body::accept
hack works like a charm: https://docs.google.com/spreadsheets/d/1QBC_54jSYGA9FQD0M9M-nJM_JOmpRnYrbN9Cew-o7tc/edit?usp=sharing
Could not find out what the Chrome issue was in the past.
We may want to do a basic check to disallow certain extensions(in all file upload widgets). Very limited security though.
investigate if
accept
attribute can be overwritten