Opened 3 years ago

Closed 3 years ago

Last modified 3 years ago

#18281 closed defect (fixed)

Exonerator does not render in Chrome (needs Content-Type: text/html)

Reported by: ericlaw Owned by: karsten
Priority: Medium Milestone:
Component: Metrics/ExoneraTor Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

https://exonerator.torproject.org/ does not render in Chrome, as it includes an X-Content-Type-Options: nosniff header but does not include a Content-Type header specifying HTML.

https://twitter.com/garrettr_/status/696776420354228224

Child Tickets

Change History (5)

comment:1 Changed 3 years ago by garrettr

Damn, you beat me to it! :-) Closing the issue I just filed, https://trac.torproject.org/projects/tor/ticket/18282, as a dupe of this one.

comment:2 Changed 3 years ago by garrettr

Actually, I'll let arma and karsten sort out which one of these should be closed as a dupe.

comment:3 Changed 3 years ago by arma

Owner: set to karsten
Status: newassigned

Karsten: this happens because weasel just set a header on the webserver side, to improve security, but that exposes the fact that exonerator has not been setting a Content-Type header.

comment:4 Changed 3 years ago by karsten

Resolution: fixed
Status: assignedclosed

Fixed, I think. Let me know if it's still broken. Thanks! Resolving.

comment:5 Changed 3 years ago by ericlaw

looks good, thanks!

Note: See TracTickets for help on using tickets.