Skip to content

test(api): prove header-injection sanitizer via staged.file_name path (#15-4)

변재혁 requested to merge feature/knowledge-download-scope into develop-log

Code review found the download-header injection test only fed the malicious CRLF/quote payload into the ignored request.fileName field, never into the DB-sourced staged.file_name that _content_disposition actually sanitizes - so the assertion passed even against a no-op sanitizer. Add a direct unit test for _content_disposition and a router test with a malicious staged.file_name, and reword the original assertion to state what it actually proves (request fileName is ignored, not that it's sanitized).

Merge request reports