mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
The media allowlist refused any upload whose multipart part had an empty or application/octet-stream Content-Type before looking at the extension or the bytes. Browsers take that header from File.type, which mobile browsers leave empty when the OS cannot classify a picked file, while the client-side gate already accepts such files on extension alone. A real JPG/MP4/MOV could pass the dialog and still be refused by the API. Only an undetermined type now falls back to the extension. The resolved type still goes through the SH-171 document/category rule, the extension pairing, and the magic-byte signature check, so an octet-stream .pdf stays refused for Completion, Before and After, and a declared type is never overridden. |
||
|---|---|---|
| .. | ||
| Configuration | ||
| Constants | ||
| DependencyInjection | ||
| DTOs | ||
| Exceptions | ||
| Helpers | ||
| Implementation | ||
| Interfaces | ||
| Validation | ||
| SeaHaven.Services.csproj | ||