[FIX] the ; in content-disposition is a separator not a terminator

According to RFC 6266,

content-disposition = "Content-Disposition" ":"
                      disposition-type *( ";" disposition-parm )

disposition-parm can't be an empty string, and thus a ; in terminal
position is not legal, even though browsers apparently work around it.
This commit is contained in:
Xavier Morel
2018-07-13 17:31:22 +02:00
parent 0bb5268cb3
commit ccbfa94d32
+1 -1
View File
@@ -81,7 +81,7 @@ class TableExporter(http.Controller):
response = request.make_response(None,
headers=[('Content-Type', 'application/vnd.ms-excel'),
('Content-Disposition', 'attachment; filename=table.xls;')],
('Content-Disposition', 'attachment; filename=table.xls')],
cookies={'fileToken': token})
workbook.save(response.stream)