{"record":{"id":"e03301d022a79229","repo":"aio-libs/aiohttp","slug":"bad-content-disposition-type-disptype-r","errorCode":null,"errorMessage":"bad content disposition type {disptype!r}","messagePattern":"bad content disposition type (.+?)","errorType":"exception","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"aiohttp/helpers.py","lineNumber":440,"sourceCode":"    \"\"\"Sets ``Content-Disposition`` header for MIME.\n\n    This is the MIME payload Content-Disposition header from RFC 2183\n    and RFC 7579 section 4.2, not the HTTP Content-Disposition from\n    RFC 6266.\n\n    disptype is a disposition type: inline, attachment, form-data.\n    Should be valid extension token (see RFC 2183)\n\n    quote_fields performs value quoting to 7-bit MIME headers\n    according to RFC 7578. Set to quote_fields to False if recipient\n    can take 8-bit file names and field values.\n\n    _charset specifies the charset to use when quote_fields is True.\n\n    params is a dict with disposition params.\n    \"\"\"\n    if not disptype or not (TOKEN > set(disptype)):\n        raise ValueError(f\"bad content disposition type {disptype!r}\")\n\n    value = disptype\n    if params:\n        lparams = []\n        for key, val in params.items():\n            if not key or not (TOKEN > set(key)):\n                raise ValueError(f\"bad content disposition parameter {key!r}={val!r}\")\n            if quote_fields:\n                if key.lower() == \"filename\":\n                    qval = quote(val, \"\", encoding=_charset)\n                    lparams.append((key, '\"%s\"' % qval))\n                else:\n                    try:\n                        qval = quoted_string(val)\n                    except ValueError:\n                        qval = \"\".join(\n                            (_charset, \"''\", quote(val, \"\", encoding=_charset))\n                        )","sourceCodeStart":422,"sourceCodeEnd":458,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/helpers.py#L422-L458","documentation":"content_disposition_header raises ValueError when the disposition type (disptype) is empty or contains characters outside the TOKEN set (RFC 2045 token characters). Valid disposition types include 'inline', 'attachment', 'form-data' — they must be non-empty and contain only token characters (no spaces, semicolons, or control chars).","triggerScenarios":"Calling content_disposition_header('') with an empty string, or passing a disposition type with invalid characters like spaces, semicolons, or non-token separators. Also triggered when set_content_disposition is called on a multipart part with an invalid type.","commonSituations":"Building Content-Disposition headers dynamically from user input without validation; passing None or empty string as disposition type; typos like 'attach ment' with a space; using a disposition type with special characters.","solutions":["Use a valid disposition type: 'inline', 'attachment', or 'form-data'","Validate the disposition type against TOKEN characters before calling the function","Sanitize user-provided disposition types by stripping invalid characters"],"exampleFix":"# before\nheader = content_disposition_header('')  # ValueError\n# or\nheader = content_disposition_header('attach;ment')  # ValueError\n\n# after\nheader = content_disposition_header('attachment')\n# or validate first\nDISPTYPES = {'inline', 'attachment', 'form-data'}\nif disptype not in DISPTYPES:\n    raise ValueError(f'Invalid disposition type: {disptype}')","handlingStrategy":"validation","validationCode":"import re\nTOKEN_RE = re.compile(r\"^[!#$%&'*+\\-.^_`|~0-9A-Za-z]+$\")\n\ndef validate_disptype(disptype: str) -> str:\n    if not disptype or not TOKEN_RE.match(disptype):\n        raise ValueError(f'Bad disposition type: {disptype!r}')\n    return disptype","typeGuard":"import re\ndef is_valid_disposition_type(dt: str) -> bool:\n    return bool(dt) and bool(re.match(r\"^[!#$%&'*+\\-.^_`|~0-9A-Za-z]+$\", dt))","tryCatchPattern":"try:\n    header = content_disposition_header(disptype)\nexcept ValueError as e:\n    if 'bad content disposition type' in str(e).lower():\n        disptype = 'attachment'  # safe default\n        header = content_disposition_header(disptype)\n    raise","preventionTips":["Use standard disposition types: inline, attachment, form-data","Validate user-provided disposition types against RFC token rules","Never pass empty strings or None as the disposition type"],"tags":["content-disposition","validation","header","rfc-2183"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}