However, although performing a client-side check of the file name can be useful, it does not guarantee that users cannot upload an unsafefile type, such as an executable file.
但是,虽然在用户端执行档案名称检查很好用,却不能保证使用者无法上载不安全的档案类型,例如可执行档。
2
Automatically inferring an "Add" operation is similarly unsafe. We don't want our SCM tool automatically adding any file which happens to show up in our working folder.