-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Some unnecessary headers #90
Comments
Yeah, sending |
And surely |
I dunno, I guess there's no spec for them, so it's unclear if browsers would process them on SVGs. |
@annevk
Yes.
@annevk Can you provide more information (or a link)? Thanks! @annevk, @domenic I'm one of the maintainers of the |
Test that with and without the header and notice the difference. (Note that this behavior is not standardized.) |
(Also, sending it for other resources does not create problems. What creates problems is if you send it for resources that are not correctly labeled.) |
@annevk Yes, that's was the intend, but I can see the confusion. I've updated to docs to make them more clear, thanks!
Thanks! |
Actually also "HTML" can be a malicious mime type, as it can obviously embed JS. (Maybe also other types such as SVG?) See https://www.youtube.com/watch?v=dBJt3eR8-bg for a talk by @hannob on that subject. Also is not this issue basically a dupe of webhintio/hint#1221 now? Or what is still to be discussed here? (Is not it fixed by webhintio/hint@5c798f5 or what was actually the purpose of this issue?) |
@rugk whatwg/misc-server is for issues with WHATWG's server setup. I doubt webhintio/hint has access to our keys to make the relevant changes. |
Ugh… yeah… So you still serve the header for all assets? So is there still something to do in this issue? Actually I only came here because it is linked on MDN.
Though I do not see how that link would be fitting here. After all, you are not discussion or indicating browsers may change their decision here or what? |
This issue is not exclusively about nosniff. |
So the link on MDN makes no sense… |
I guess we can close this now. |
Based on https://sonarwhal.com/scanner/82d0ae4e-aa8d-4b9b-9d32-24c1b0817136
The text was updated successfully, but these errors were encountered: