Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-1310

The X-Content-Type-Options header should be set as 'nosniff'

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.0.0
    • 1.1.0
    • AdminUI
    • None

    Description

      For every response containing a message body, the Admin UI should include a single Content-type header that correctly and unambiguously states the MIME type of the content in the response body.
       
      Additionally, the response header "X-Content-Type-Options: nosniff" should be returned in all responses to reduce the likelihood that browsers will interpret content in a way that disregards the explicit Content-type header.

      Attachments

        Activity

          People

            pzampino Philip Zampino
            pzampino Philip Zampino
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: