> At least in the case of Firefox for that particular case on Windows the > filename will be sanitized...
Yes, but Firefox is an exception, not a rule; and even that mechanism is very imperfect (it relies on explicit mappings that are not guaranteed to be in sync with other OS components; when downloading a less known MIME type, like image/jpeg2000, the user is still in trouble). /mz