<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>38364</bug_id>
          
          <creation_ts>2010-04-29 17:57:00 -0700</creation_ts>
          <short_desc>MIME typo in LayoutTests/http/tests/security/xss-DENIED-mime-type-execute-as-html.html</short_desc>
          <delta_ts>2010-05-02 14:40:00 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Tools / Tests</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>37358</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="David Kilzer (:ddkilzer)">ddkilzer</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>abarth</cc>
    
    <cc>inferno</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>219307</commentid>
    <comment_count>0</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2010-04-29 17:57:00 -0700</bug_when>
    <thetext>I believe there is a typo in LayoutTests/http/tests/security/xss-DENIED-mime-type-execute-as-html.html where &quot;application-javascript&quot; is used instead of &quot;application/javascript&quot;.

Without a &quot;/&quot; in the MIME type, the content returned can be sniffed per &lt;http://tools.ietf.org/html/draft-abarth-mime-sniff-04&gt;, and because it starts out with a &lt;script&gt; tag, is likely to be sniffed as &quot;text/html&quot;.

Was the use of &quot;application-javascript&quot; intentional or just a typo?

See Bug 37358 for the original fix and test case.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>219310</commentid>
    <comment_count>1</comment_count>
      <attachid>54765</attachid>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2010-04-29 18:01:00 -0700</bug_when>
    <thetext>Created attachment 54765
Patch v1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>219315</commentid>
    <comment_count>2</comment_count>
    <who name="Abhishek Arya">inferno</who>
    <bug_when>2010-04-29 18:14:48 -0700</bug_when>
    <thetext>Yes, David it is a typo. Sorry about that.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>219611</commentid>
    <comment_count>3</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2010-04-30 14:05:58 -0700</bug_when>
    <thetext>Committed r58604: &lt;http://trac.webkit.org/changeset/58604&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>54765</attachid>
            <date>2010-04-29 18:01:00 -0700</date>
            <delta_ts>2010-04-29 18:26:56 -0700</delta_ts>
            <desc>Patch v1</desc>
            <filename>bug-38364-20100429180059.patch</filename>
            <type>text/plain</type>
            <size>1624</size>
            <attacher name="David Kilzer (:ddkilzer)">ddkilzer</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxv
ZwppbmRleCA4YzIyNTkyM2ZiZDc3ZWU0NzkzNjYyNGYxNjRjZTM5YmExN2VkYTFiLi5jNDQwNzFi
NzY0NzRkYjZmMTI0YjliMDVlOWM3NmMyM2IzYWYwNmM1IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0
cy9DaGFuZ2VMb2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAK
KzIwMTAtMDQtMjkgIERhdmlkIEtpbHplciAgPGRka2lsemVyQGFwcGxlLmNvbT4KKworICAgICAg
ICA8aHR0cDovL3dlYmtpdC5vcmcvYi8zODM2ND4gTUlNRSB0eXBvIGluIExheW91dFRlc3RzL2h0
dHAvdGVzdHMvc2VjdXJpdHkveHNzLURFTklFRC1taW1lLXR5cGUtZXhlY3V0ZS1hcy1odG1sLmh0
bWwKKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICAqIGh0
dHAvdGVzdHMvc2VjdXJpdHkveHNzLURFTklFRC1taW1lLXR5cGUtZXhlY3V0ZS1hcy1odG1sLmh0
bWw6CisgICAgICAgIEZpeGVkIE1JTUUgdHlwbyBmcm9tICJhcHBsaWNhdGlvbi1qYXZhc2NyaXB0
IiB0bworICAgICAgICAiYXBwbGljYXRpb24vamF2YXNjcmlwdCIuCisKIDIwMTAtMDQtMjkgIFlh
YXIgU2Nobml0bWFuICA8eWFhckBjaHJvbWl1bS5vcmc+CiAKICAgICAgICAgTm90IFJldmlld2Vk
LgpkaWZmIC0tZ2l0IGEvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS94c3MtREVOSUVE
LW1pbWUtdHlwZS1leGVjdXRlLWFzLWh0bWwuaHRtbCBiL0xheW91dFRlc3RzL2h0dHAvdGVzdHMv
c2VjdXJpdHkveHNzLURFTklFRC1taW1lLXR5cGUtZXhlY3V0ZS1hcy1odG1sLmh0bWwKaW5kZXgg
Mjc5NDZjNjZiN2UxYWQxZmE3ZjE2NjI1NWYwYmIxZmJkY2MxMGFmOC4uNTY5OWU0NGQ2MmQwZTZm
OTY5NmM5MmM0YzU1N2I2YmRhYjJlNDNjYiAxMDA2NDQKLS0tIGEvTGF5b3V0VGVzdHMvaHR0cC90
ZXN0cy9zZWN1cml0eS94c3MtREVOSUVELW1pbWUtdHlwZS1leGVjdXRlLWFzLWh0bWwuaHRtbAor
KysgYi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3hzcy1ERU5JRUQtbWltZS10eXBl
LWV4ZWN1dGUtYXMtaHRtbC5odG1sCkBAIC05LDcgKzksNyBAQCBpZiAod2luZG93LmxheW91dFRl
c3RDb250cm9sbGVyKSB7CiB9CiAKIHZhciBtaW1lX3R5cGVzID0gWyJhcHBsaWNhdGlvbi9hdG9t
K3htbCIsICJhcHBsaWNhdGlvbi9qc29uIiwKLSAgICAgICAgICAgICAgICAgICJhcHBsaWNhdGlv
bi1qYXZhc2NyaXB0IiwgImFwcGxpY2F0aW9uL3Jzcyt4bWwiLCAidGV4dC8iLAorICAgICAgICAg
ICAgICAgICAgImFwcGxpY2F0aW9uL2phdmFzY3JpcHQiLCAiYXBwbGljYXRpb24vcnNzK3htbCIs
ICJ0ZXh0LyIsCiAgICAgICAgICAgICAgICAgICAidGV4dC9jYWNoZS1tYW5pZmVzdCIsICJ0ZXh0
L2NzcyIsICJ0ZXh0L2VjbWFzY3JpcHQiLAogICAgICAgICAgICAgICAgICAgInRleHQvamF2YXNj
cmlwdCIsICJ0ZXh0L2phdmFzY3JpcHQxLjEiLCAidGV4dC9qYXZhc2NyaXB0MS4yIiwKICAgICAg
ICAgICAgICAgICAgICJ0ZXh0L2phdmFzY3JpcHQxLjMiLCAidGV4dC9qc2NyaXB0IiwgInRleHQv
bGl2ZXNjcmlwdCIsICJ0ZXh0L3BsYWluIl07Cg==
</data>
<flag name="review"
          id="38801"
          type_id="1"
          status="+"
          setter="levin"
    />
          </attachment>
      

    </bug>

</bugzilla>