From 3c30c3975ae9b56664f3049c4b71472c7ef96a62 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Tue, 18 Aug 2026 19:49:42 -0700 Subject: Print the raw-content headers with the rest --- source/ui-blob.c | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) (limited to 'source/ui-blob.c') diff --git a/source/ui-blob.c b/source/ui-blob.c index db1d0c1..8f68d04 100644 --- a/source/ui-blob.c +++ b/source/ui-blob.c @@ -205,13 +205,7 @@ void cgit_print_blob(const char *hex, char *path, const char *head, int file_onl else ctx.page.mimetype = "text/plain"; ctx.page.filename = path; - - // The bytes are whatever the repository holds, so the browser is told - // not to guess a type of its own from them and not to load anything - // they reference. Both must go out before cgit_print_http_headers, - // which closes the header block. - html("X-Content-Type-Options: nosniff\n"); - html("Content-Security-Policy: default-src 'none'\n"); + ctx.page.untrusted = 1; cgit_print_http_headers(); html_raw(buf, size); free(buf); -- cgit v2.8.0