mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-04 14:52:10 +00:00
The completion-document endpoint persisted whatever file it received: the only checks were non-null, non-empty, and a 30 MB request limit. Its sibling media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and a magic-byte signature check since SH-116. Validate before the file reaches storage, so a rejected upload leaves nothing behind. An undetermined content type is accepted only alongside a .pdf name and a %PDF- signature, because the browser leaves File.type empty when the OS cannot classify the file and the completion-doc dialog already allows that. |
||
|---|---|---|
| .. | ||
| .config | ||
| Controllers | ||
| DTOs | ||
| Filters | ||
| Helper | ||
| HostedServices | ||
| Infrastructure | ||
| Middleware | ||
| Models | ||
| Observability | ||
| Options | ||
| Properties | ||
| wwwroot | ||
| Api.SeaHavenIndustries.csproj | ||
| Api.SeaHavenIndustries.http | ||
| appsettings.Development.json | ||
| appsettings.json | ||
| appsettings.Production.json | ||
| aws-beanstalk-tools-defaults.json | ||
| db.txt | ||
| Program.cs | ||