Lts1sds 3fdf04597e
fix(gateway): classify Windows SVG MIME alias as active content (#5594)
* fix(gateway): classify Windows SVG MIME alias as active content

Treat Windows' image/svg alias like the standard image/svg+xml active content type.

* test(gateway): cover Windows SVG MIME alias

Pin image/svg classification independently of the host MIME database.

* docs(utils): document platform MIME aliases

Record the shared active-content classification invariant.
2026-09-20 15:23:19 +08:00

45 lines
1.5 KiB
Python

"""Content-sampled text/binary detection shared by routers and harness tools."""
from __future__ import annotations
from pathlib import Path
def is_text_file_by_content(path: Path, sample_size: int = 8192) -> bool:
"""Check if file is text by examining content for null bytes."""
try:
with open(path, "rb") as f:
chunk = f.read(sample_size)
# Text files shouldn't contain null bytes
return b"\x00" not in chunk
except Exception:
return False
# Exact matches include platform MIME aliases; the helper also treats every
# ``+xml`` subtype as active content.
ACTIVE_CONTENT_MIME_TYPES = {
"text/html",
"application/xhtml+xml",
"image/svg",
"image/svg+xml",
"text/xml",
"application/xml",
"text/xsl",
}
def _is_active_content_mime_type(mime_type: str | None) -> bool:
"""Return whether a browser can run script when rendering *mime_type* inline.
Beyond HTML, this covers every WHATWG XML MIME type (``text/xml``,
``application/xml``, or a ``+xml`` subtype), Windows' ``image/svg`` alias,
and ``text/xsl``, which Blink also renders as XML: any XML document can
carry an XHTML-namespaced ``<script>``, so ``report.xml`` or ``feed.rss``
is as dangerous as ``page.html`` when opened in the application origin.
"""
if mime_type is None:
return False
mime_type = mime_type.lower()
return mime_type in ACTIVE_CONTENT_MIME_TYPES or mime_type.endswith("+xml")