2 ms·
As a side issue here I can't believe sniffing is still the default. From basically the day it existed it's been considered a best practise to send that header
by technion 2y ago
As a side issue here I can't believe sniffing is still the default.
From basically the day it existed it's been considered a best practise to send that header with every request, because there might be a vulnerability introduced otherwise . I've never heard of anyone relying on it. Why can't modern browsers flip the default on this internet Explorer era magic footgun?
- bawolff 2y ago> As a side issue here I can't believe sniffing is still the default It isn't the default in modern browsers, or at least not in the sense you mean. The header still controls some things, but even without it, browsers will not sniff something served as content type image/png as html or anything like that. How modern browsers interpret that is different than IE.
- dgoldstein0 2y agoI think it's still the default with text/plain. Haven't verified that though