contentTypeOptions property
Stops a browser guessing a type other than the one you sent.
Without it, a text file a user uploaded can be sniffed as HTML and run.
Implementation
final String? contentTypeOptions;
Stops a browser guessing a type other than the one you sent.
Without it, a text file a user uploaded can be sniffed as HTML and run.
final String? contentTypeOptions;