W3C home > Mailing lists > Public > whatwg@whatwg.org > November 2012

[whatwg] [mimesniff] The X-Content-Type-Options header

From: Gordon P. Hemsley <gphemsley@gmail.com>
Date: Fri, 16 Nov 2012 17:19:37 -0500
Message-ID: <CAH4e3M61gS3ENDfgYRaQc-HdGinY18hV80DHW35-NWnahtzFeA@mail.gmail.com>
To: whatwg List <whatwg@whatwg.org>

Microsoft introduced the X-Content-Type-Options header in IE8 back in 2008:


I would like to integrate the header into mimesniff and describe its
proper usage.

Right now, it allows one parameter: 'nosniff'. I would like to allow
the presence of this parameter to set the 'no-sniff flag' that I just
introduced into mimesniff (in addition to that flag's existing


But I would also like to fully spec the header, while leaving open the
possibility that other values may be added in the future.

In addition, I would like to, if I could, also allow the header to be
specified without the 'X-' prefix (so as 'Content-Type-Options'), for
that reason (and because of best current practice).

Does anyone have any questions, comments, or objections about this issue?

Gordon P. Hemsley
Received on Friday, 16 November 2012 22:24:41 UTC

This archive was generated by hypermail 2.3.1 : Monday, 13 April 2015 23:09:17 UTC