hugo/resources
Bjørn Erik Pedersen 44954497bc
Always use content to resolve content type in resources.GetRemote
This is a security hardening measure; don't trust the URL extension or any `Content-Type`/`Content-Disposition` header on its own, always look at the file content using Go's `http.DetectContentType`.

This commit also adds ttf and otf media type definitions to Hugo.

Fixes #9302
Fixes #9301
2021-12-17 09:50:28 +01:00
..
images Always use content to resolve content type in resources.GetRemote 2021-12-17 09:50:28 +01:00
internal
jsconfig
page Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
postpub Always use content to resolve content type in resources.GetRemote 2021-12-17 09:50:28 +01:00
resource Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
resource_factories Always use content to resolve content type in resources.GetRemote 2021-12-17 09:50:28 +01:00
resource_transformers Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
testdata
errorResource.go Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
image.go
image_cache.go
image_extended_test.go
image_test.go
post_publish.go
resource.go Always use content to resolve content type in resources.GetRemote 2021-12-17 09:50:28 +01:00
resource_cache.go
resource_cache_test.go
resource_metadata.go
resource_metadata_test.go
resource_spec.go Always use content to resolve content type in resources.GetRemote 2021-12-17 09:50:28 +01:00
resource_test.go
testhelpers_test.go Add some basic security policies with sensible defaults 2021-12-16 09:40:22 +01:00
transform.go Allow user to handle/ignore errors in resources.Get 2021-12-10 11:10:41 +01:00
transform_test.go