refactor: use mime_content_type to reliably detect MIME from file contents instead of relying on unreliable Content-Type headers
This commit is contained in:
parent
335180d7a1
commit
9cf16ca0c4
1 changed files with 4 additions and 5 deletions
|
|
@ -82,8 +82,9 @@ private function attachOne(Post $post, string $url): ?array
|
|||
|
||||
/**
|
||||
* Stream the URL to a temp file, aborting once we exceed the largest
|
||||
* configured per-type cap (video). The actual per-type limit is
|
||||
* enforced by the caller after we know the MIME.
|
||||
* configured per-type cap (video). MIME is sniffed from the file's
|
||||
* magic bytes — far more reliable than trusting the upstream
|
||||
* `Content-Type` header (CDNs misconfigure, attackers spoof).
|
||||
*
|
||||
* @return array{path: string, mime: ?string, bytes: int}|null
|
||||
*/
|
||||
|
|
@ -118,11 +119,9 @@ private function download(string $url): ?array
|
|||
return null;
|
||||
}
|
||||
|
||||
$mime = trim(explode(';', (string) $response->header('Content-Type'))[0]);
|
||||
|
||||
return [
|
||||
'path' => $temp,
|
||||
'mime' => $mime !== '' ? $mime : null,
|
||||
'mime' => mime_content_type($temp) ?: null,
|
||||
'bytes' => $bytes,
|
||||
];
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue