mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-02 15:33:21 +00:00
The completion-document endpoint persisted whatever file it received: the only checks were non-null, non-empty, and a 30 MB request limit. Its sibling media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and a magic-byte signature check since SH-116. Validate before the file reaches storage, so a rejected upload leaves nothing behind. An undetermined content type is accepted only alongside a .pdf name and a %PDF- signature, because the browser leaves File.type empty when the OS cannot classify the file and the completion-doc dialog already allows that. |
||
|---|---|---|
| .. | ||
| Configuration | ||
| Constants | ||
| DependencyInjection | ||
| DTOs | ||
| Exceptions | ||
| Helpers | ||
| Implementation | ||
| Interfaces | ||
| Validation | ||
| SeaHaven.Services.csproj | ||