Comment 196 for bug 25830

Revision history for this message
In , Vincent+moz (vincent+moz) wrote :

(In reply to comment #161)
> Content-disposition is described in http://www.faqs.org/rfcs/rfc2183. It is
> also mentioned in the "Security considerations" section of the HTTP spec
> (http://www.faqs.org/rfcs/rfc2616), although it's not clear what security
> considerations it's talking about.

The security considerations concern the directory path information. I've mentioned it in bug 185618 comment 45.

Concerning this bug 57342, whose goal is to be able to view the contents for unsupported media types, there's nothing to save, therefore no security problems.

> Btw, I'm not sure I agree with the way you equate "non-standard" with "wrong".

When a non-standard feature modifies the normal behavior documented in standards (in a non-optional way), this is a bug.