Code review comment for lp:~mkanat/loggerhead/raw-controller

Revision history for this message
Max Kanat-Alexander (mkanat) wrote :

> If we are worried about XSS, why not start by having raw just return
> everything as application/octet-stream until we figure out how to
> protect against it?

  Because we already have /download/ for that. This is about displaying content in the browser.

« Back to merge proposal