fix: add X-Content-Type-Options nosniff header to Apache htaccess#40682
fix: add X-Content-Type-Options nosniff header to Apache htaccess#40682lbajsarowicz wants to merge 1 commit intomagento:2.4-developfrom
Conversation
|
Hi @lbajsarowicz. Thank you for your contribution!
Allowed build names are:
You can find more information about the builds here For more details, review the Code Contributions documentation. |
|
The security team has been informed about this pull request due to the presence of risky security keywords. For security vulnerability reports, please visit Adobe's vulnerability disclosure program on HackerOne or email psirt@adobe.com. |
|
@magento create issue |
|
The security team has been informed about this pull request due to the presence of risky security keywords. For security vulnerability reports, please visit Adobe's vulnerability disclosure program on HackerOne or email psirt@adobe.com. |
Description
Add the
X-Content-Type-Options: nosniffsecurity header inpub/.htaccessalongside the existingX-Frame-Optionsheader.Problem
The
.htaccessconfiguration setsX-Frame-Options: SAMEORIGINto prevent clickjacking but does not setX-Content-Type-Options: nosniff. Without this header, browsers may MIME-sniff responses and interpret files as a different content type than declared, which can lead to:/media/being interpreted as executable HTML/JavaScriptSolution
Add
Header set X-Content-Type-Options "nosniff"in themod_headersblock ofpub/.htaccess. This is set at the top-level.htaccessso it applies to all responses served through Apache.References
Files Changed
pub/.htaccess⭐ Support my work
Do you like the fix? Remember to react with "👍🏻" to get it merged faster,
Then Sponsor me on Github so I can spend more time on fixing issues like this one.
Learn more at https://github.com/sponsors/lbajsarowicz
Resolved issues: