Quote Multipart/Form-Data Field Names (#6782)

This commit is contained in:
Mark Kraus
2018-05-08 09:18:09 +05:00
committed by Ilya
parent 4737ebae20
commit f54a0ab033
@@ -1817,7 +1817,8 @@ namespace Microsoft.PowerShell.Commands
private StringContent GetMultipartStringContent(Object fieldName, Object fieldValue)
{
var contentDisposition = new ContentDispositionHeaderValue("form-data");
contentDisposition.Name = LanguagePrimitives.ConvertTo<String>(fieldName);
// .NET does not enclose field names in quotes, however, modern browsers and curl do.
contentDisposition.Name = "\"" + LanguagePrimitives.ConvertTo<String>(fieldName) + "\"";
var result = new StringContent(LanguagePrimitives.ConvertTo<String>(fieldValue));
result.Headers.ContentDisposition = contentDisposition;
@@ -1833,7 +1834,8 @@ namespace Microsoft.PowerShell.Commands
private StreamContent GetMultipartStreamContent(Object fieldName, Stream stream)
{
var contentDisposition = new ContentDispositionHeaderValue("form-data");
contentDisposition.Name = LanguagePrimitives.ConvertTo<String>(fieldName);
// .NET does not enclose field names in quotes, however, modern browsers and curl do.
contentDisposition.Name = "\"" + LanguagePrimitives.ConvertTo<String>(fieldName) + "\"";
var result = new StreamContent(stream);
result.Headers.ContentDisposition = contentDisposition;
@@ -1850,7 +1852,8 @@ namespace Microsoft.PowerShell.Commands
private StreamContent GetMultipartFileContent(Object fieldName, FileInfo file)
{
var result = GetMultipartStreamContent(fieldName: fieldName, stream: new FileStream(file.FullName, FileMode.Open));
result.Headers.ContentDisposition.FileName = file.Name;
// .NET does not enclose field names in quotes, however, modern browsers and curl do.
result.Headers.ContentDisposition.FileName = "\"" + file.Name + "\"";
return result;
}