Cap attachment filenames at 128 chars server-side
A 250-char multipart filename was accepted and echoed verbatim in Content-Disposition. SanitizeFilename already truncates; lower the cap from 255 to 128 so DB rows and header echoes stay bounded (#248).
This commit is contained in:
@@ -105,4 +105,9 @@ func TestSanitizeFilename(t *testing.T) {
|
||||
if got := SanitizeFilename(long); len(got) != MaxFilenameLen {
|
||||
t.Errorf("long name len = %d want %d", len(got), MaxFilenameLen)
|
||||
}
|
||||
// issue #248: a 250-char multipart filename must truncate to the cap
|
||||
repro := strings.Repeat("b", 246) + ".txt"
|
||||
if got := SanitizeFilename(repro); len(got) != MaxFilenameLen {
|
||||
t.Errorf("repro name len = %d want %d", len(got), MaxFilenameLen)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user