mirror of
https://github.com/gosticks/wordpress-develop.git
synced 2026-08-11 12:20:22 +00:00
Introduce send_nosniff_header() and use it to turn off content sniffing in supported browsers. Fixes #10671 props chrisscott and niallkennedy.
git-svn-id: https://develop.svn.wordpress.org/trunk@13409 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
@@ -649,4 +649,17 @@ function win_is_writable($path) {
|
||||
unlink($path);
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Send a HTTP header to disable content type sniffing in browsers which support it.
|
||||
*
|
||||
* @link http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-v-comprehensive-protection.aspx
|
||||
* @link http://src.chromium.org/viewvc/chrome?view=rev&revision=6985
|
||||
*
|
||||
* @since 3.0.0.
|
||||
* @return none
|
||||
*/
|
||||
function send_nosniff_header() {
|
||||
@header( 'X-Content-Type-Options: nosniff' );
|
||||
}
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user