Logout

Alt-N Discussion Groups > Discussions > Errors caused by header 'X-Content-Type-Options: nosniff'

 [F] Alt-N Discussion Groups  / Discussions  /

Errors caused by header 'X-Content-Type-Options: nosniff'

[Sarandis, Harris]
Harris Sarandis
Newbie
Newbie
Posts: 3
Harris Sarandis - 05:05am, Mar 19 2021

Running MDeamon via IIS.

Adding the 'X-Content-Type-Options: nosniff' response header, errors (see below) are thrown in Chrome's console when openning the Worldclient's Compose or Email Templates pages - and the CKEditor box does not appear.
From what I get, the cke configuration is not returned (blocked) to the 'ReturnConfig' request, and so cke looks for the (default?) 'flat' skin in the wrong folder.
Copying the folder 'flat' from ckeditor4/skins to ckeditor/skins will cause the edit box to appear, but with the default config (as the config settings have not been loaded).

Errors:
Refused to execute script from '/WorldClient.dll?Session=xxxxxx&View=Compose&ReturnConfig=1&t=J0BE' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.
Refused to apply style from '/ckeditor/skins/flat/editor.css?t=J0BE' because its MIME type ('text/html') is not a supported stylesheet MIME type, and strict MIME checking is enabled.

  (older msg: 3)All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items

Harris Sarandis - Jun 10, 2021 1:36 am (#4 Total: 5)  

 

Photo of Author
Harris Sarandis
Newbie
Newbie
Posts: 3
Replying to: Arron Caruth (May 17, 2021 8:17 am)
Which version are you currently using?   I'm unable to reproduce the issue so far and would like to test...

Hello,

Just installed v21.0.2, re-enabled the header.
Still getting the following in crome's console, when selecting 'compose' from the settings:
"Refused to execute script from 'https://<mydomain.com>/WorldClient.dll?Session=<XXXXXX>&View=Compose&ReturnConfig=1&t=L0QD' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.

However, the cke box does open now - just, from what it seems, opening the office(?) template (the one with a blue bar at the bottom).
By disabling the header, the error goes away, and the regular template (same as when composing new mail) is being displayed.

Summary: the error is still there, so the cke customization message is ignored/blocked, so the default cke template is used, but I would guess that cke's defaults have been changed/updated, and so, the default template is loaded succesfully.

Arron Caruth - Jun 10, 2021 8:25 am (#5 Total: 5)  

Guest User  

Photo of Author
Posts: 1
I'm glad to hear that it's working for you now. 

We'll take another look and see if we can make additional changes to fix the error you are seeing. 

--
Arron Caruth
Vice President of Product Development
o: 817-601-3222    e: Arron.Caruth@mdaemon.com

MDaemon Technologies
Simple Secure Email
Visit us on www.mdaemon.com | Facebook | LinkedIn | YouTube
Sent using the MDaemon Email Server

On Thu, 10 Jun 2021 01:36:44 -0500, "lists-discuss@mdaemon.com (Harris Sarandis)" <lists-discuss@mdaemon.com> wrote:
Hello,

Just installed v21.0.2, re-enabled the header.
Still getting the following in crome's console, when selecting 'compose' from the settings:
"Refused to execute script from 'https://<mydomain.com>/WorldClient.dll?Session=<XXXXXX>&View=Compose&ReturnConfig=1&t=L0QD' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.

However, the cke box does open now - just, from what it seems, opening the office(?) template (the one with a blue bar at the bottom).
By disabling the header, the error goes away, and the regular template (same as when composing new mail) is being displayed.

Summary: the error is still there, so the cke customization message is ignored/blocked, so the default cke template is used, but I would guess that cke's defaults have been changed/updated, and so, the default template is loaded succesfully.


View/reply at Errors caused by header 'X-Content-Type-Options: nosniff'
--DISCUSS--------------------------------------------------------------
This mailing list is for questions and discussion regarding Alt-N
products.  To unsubscribe from this mailing list send an email to
discuss-unsubscribe@mdaemon.com .
--DISCUSS--------------------------------------------------------------


-----------------------------------------------------------------------
These forums are provided by MDaemon Technologies for user-to-user 
support and discussion.  MDaemon staff members may participate in the 
forums periodically but please recognize that this is not the official
method of receiving technical support. To receive personal technical 
support please use the form here:
http://www.mdaemon.com/Support/RequestSupport/
-----------------------------------------------------------------------

--DISCUSS--------------------------------------------------------------
This mailing list is for questions and discussion regarding Alt-N
products.  To unsubscribe from this mailing list send an email to
discuss-unsubscribe@mdaemon.com .
--DISCUSS--------------------------------------------------------------


-----------------------------------------------------------------------
These forums are provided by MDaemon Technologies for user-to-user
support and discussion.  MDaemon staff members may participate in the
forums periodically but please recognize that this is not the official
method of receiving technical support. To receive personal technical
support please use the form here:
http://www.mdaemon.com/Support/RequestSupport/
-----------------------------------------------------------------------



  All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items



 Content:

Read New | Search

 Guest:

Email to Admin



You are visiting as a Guest user.