Encode Unicode video titles in playback response headers
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
import { existsSync } from 'node:fs'
|
import { existsSync } from 'node:fs'
|
||||||
import { sendPathWithRange } from '~/server/utils/httpRange'
|
import { sendPathWithRange } from '~/server/utils/httpRange'
|
||||||
|
import { inlineFilename } from '~/shared/content-disposition.mjs'
|
||||||
|
|
||||||
export default defineEventHandler((event) => {
|
export default defineEventHandler((event) => {
|
||||||
const { owner } = assertLibraryOwner(event)
|
const { owner } = assertLibraryOwner(event)
|
||||||
@@ -11,7 +12,7 @@ export default defineEventHandler((event) => {
|
|||||||
throw createError({ statusCode: 404, statusMessage: 'Video file is missing' })
|
throw createError({ statusCode: 404, statusMessage: 'Video file is missing' })
|
||||||
}
|
}
|
||||||
return sendPathWithRange(event, path, 'video/mp4', {
|
return sendPathWithRange(event, path, 'video/mp4', {
|
||||||
'Content-Disposition': `inline; filename="${safeDownloadName(clipTitle(clip))}.mp4"`,
|
'Content-Disposition': inlineFilename(`${safeDownloadName(clipTitle(clip))}.mp4`),
|
||||||
'Cache-Control': 'private, max-age=0, must-revalidate'
|
'Cache-Control': 'private, max-age=0, must-revalidate'
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
/** ASCII header fallback plus UTF-8 filename; titles may contain emoji or smart punctuation. */
|
||||||
|
export function inlineFilename(name) {
|
||||||
|
const clean=String(name).replace(/[\r\n\x00-\x1f\x7f]/g,'').toWellFormed()
|
||||||
|
const ascii=clean.replace(/[^\x20-\x7e]/g,'_').replace(/["\\]/g,'_') || 'video.mp4'
|
||||||
|
const encoded=encodeURIComponent(clean || 'video.mp4').replace(/['()*]/g,c=>'%'+c.charCodeAt(0).toString(16).toUpperCase())
|
||||||
|
return `inline; filename="${ascii}"; filename*=UTF-8''${encoded}`
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user