Add the X-Content-Type-Options header
headers-xcto
Browsers guess the type of a response when the server does not say. Sending nosniff stops an uploaded file being run as script.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Go to Rules > Transform Rules > Modify Response Header
- 2 Create a rule that sets X-Content-Type-Options to the desired value
- 3 Deploy the rule
Header name: X-Content-Type-Options
Value: nosniffAWS CloudFront
- 1 Create a Response Headers Policy in CloudFront
- 2 Attach the policy to your distribution's behavior
Custom header:
Name: X-Content-Type-Options
Value: nosniff
Override origin: YesVercel
- 1 Add a headers entry to your vercel.json
- 2 Redeploy
json
{
"headers": [
{
"source": "/(.*)",
"headers": [
{ "key": "X-Content-Type-Options", "value": "nosniff" }
]
}
]
}Netlify
- 1 Add a headers section to your netlify.toml or _headers file
- 2 Redeploy
toml
[[headers]]
for = "/*"
[headers.values]
X-Content-Type-Options = "nosniff"Nginx
- 1 Add the header directive to your server or location block
- 2 Test config with nginx -t, then reload
nginx
add_header X-Content-Type-Options "nosniff" always;Apache
- 1 Make sure mod_headers is enabled
- 2 Add the Header directive to your .htaccess or VirtualHost
apacheconf
Header always set X-Content-Type-Options "nosniff"Caddy
- 1 Add a header directive to your Caddyfile
- 2 Reload Caddy
caddyfile
header X-Content-Type-Options "nosniff"Next.js
- 1 Add a headers function to your next.config.js
- 2 Rebuild and redeploy
javascript
// next.config.js
module.exports = {
async headers() {
return [{
source: "/(.*)",
headers: [
{ key: "X-Content-Type-Options", value: "nosniff" },
],
}];
},
};Express
- 1 Use the helmet middleware (recommended) or set the header manually
- 2 Restart your server
javascript
// Using helmet (recommended)
const helmet = require("helmet");
app.use(helmet());
// Or manually
app.use((req, res, next) => {
res.setHeader("X-Content-Type-Options", "nosniff");
next();
});Django
- 1 Add or update the setting in your settings.py
- 2 Redeploy
python
# settings.py
# Django's SecurityMiddleware handles several headers.
# For custom headers, use middleware or django-csp.Laravel
- 1 Add a middleware that sets the header
- 2 Register it in your HTTP kernel
php
// app/Http/Middleware/SecurityHeaders.php
public function handle($request, Closure $next)
{
$response = $next($request);
$response->headers->set('X-Content-Type-Options', 'nosniff');
return $response;
}Rails
- 1 Set the header in your ApplicationController or config
ruby
# config/application.rb
config.action_dispatch.default_headers.merge!(
'X-Content-Type-Options' => 'nosniff'
)Spring Boot
- 1 Configure the header in your SecurityFilterChain
java
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.headers(h -> h
.addHeaderWriter(new StaticHeadersWriter("X-Content-Type-Options", "nosniff"))
);
return http.build();
}WordPress
- 1 Add the header via your theme's functions.php or .htaccess
- 2 A security plugin like HTTP Headers can also help
php
# .htaccess (Apache)
Header always set X-Content-Type-Options "nosniff"
# Or in functions.php
add_action('send_headers', function() {
header('X-Content-Type-Options: nosniff');
});Nuxt
- 1 Add the header to your nuxt.config.ts routeRules
- 2 Rebuild and redeploy
typescript
// nuxt.config.ts
export default defineNuxtConfig({
routeRules: {
'/**': {
headers: { 'X-Content-Type-Options': 'nosniff' },
},
},
});ASP.NET
- 1 Add middleware in your Program.cs or Startup.cs
csharp
app.Use(async (context, next) =>
{
context.Response.Headers.Append("X-Content-Type-Options", "nosniff");
await next();
});Does your app still have this?
Scan your domain