Skip to content

Change Content-Disposition: inline to attachment in f.php#8344

Merged
Alkarex merged 1 commit intoFreshRSS:edgefrom
Inverle:favicon-attachment
Dec 24, 2025
Merged

Change Content-Disposition: inline to attachment in f.php#8344
Alkarex merged 1 commit intoFreshRSS:edgefrom
Inverle:favicon-attachment

Conversation

@Inverle
Copy link
Member

@Inverle Inverle commented Dec 24, 2025

Some misconfigured instances may be stripping out the CSP header that f.php sends, which can be mitigated by forcing the browser to download the image instead of displaying it and executing JS code from unsanitized SVGs for example.

Contributes to #8263 and #7924
(improving security when CSP is not present)

@Inverle Inverle added this to the 1.28.1 milestone Dec 24, 2025
@Inverle Inverle requested a review from Alkarex December 24, 2025 20:06
@Alkarex Alkarex merged commit 7e5d2d0 into FreshRSS:edge Dec 24, 2025
1 check passed
@Inverle Inverle deleted the favicon-attachment branch December 24, 2025 20:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants