Is HttpPostedFile.ContentType a flawless way to validate an uploaded file?

前端 未结 3 1714
太阳男子
太阳男子 2020-12-19 05:42

I want to validate the file type to make sure the user is uploading an image of type JPEG, GIF, or PNG. Instead of checking the file extension, I figured using HttpPostedFil

3条回答
  •  臣服心动
    2020-12-19 06:24

    Using the extension is probably safer. The ContentType is sent in the http request from the client. If you test for the extension, the user can change the extension of an exe to jpg, but it won't run as an exe.

提交回复
热议问题