Skip to content
Snippets Groups Projects
Commit 7aa3b104 authored by Andreas Gohr's avatar Andreas Gohr
Browse files

added some comments about new XSS protection to mime.conf

darcs-hash:20070224131623-7ad00-cd82685db94b50be942a6d71293010aa8fdabdfa.gz
parent 26ceae18
No related branches found
No related tags found
No related merge requests found
......@@ -17,14 +17,6 @@ ppt application/mspowerpoint
rtf application/msword
swf application/x-shockwave-flash
# You should enable HTML and Text uploads only for restricted Wikis.
# Spammers are known to upload spam pages through unprotected Wikis.
#html text/html
#htm text/html
#txt text/plain
#conf text/plain
#xml text/xml
rpm application/octet-stream
deb application/octet-stream
......@@ -40,3 +32,17 @@ odi application/vnd.oasis.opendocument.image
odp application/vnd.oasis.opendocument.presentation
ods application/vnd.oasis.opendocument.spreadsheet
odt application/vnd.oasis.opendocument.text
# You should enable HTML and Text uploads only for restricted Wikis.
# Spammers are known to upload spam pages through unprotected Wikis.
# Note: Enabling HTML opens Cross Site Scripting vulnerabilities
# through JavaScript. Only enable this with trusted users. You
# need to disable the iexssprotect option additionally to
# adding the mime type here
#html text/html
#htm text/html
#txt text/plain
#conf text/plain
#xml text/xml
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment