From 3c30c3975ae9b56664f3049c4b71472c7ef96a62 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Tue, 18 Aug 2026 19:49:42 -0700 Subject: Print the raw-content headers with the rest --- source/ui-plain.c | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) (limited to 'source/ui-plain.c') diff --git a/source/ui-plain.c b/source/ui-plain.c index 5ba650b..bbd6991 100644 --- a/source/ui-plain.c +++ b/source/ui-plain.c @@ -80,12 +80,7 @@ static int print_object(const struct object_id *oid, const char *path) ctx.page.mimetype = mimetype; if (!ctx.repo->enable_html_serving) { - // The bytes are whatever the repository holds, so the browser - // is told not to guess a type of its own and not to load - // anything they reference. Both lines must go out before - // cgit_print_http_headers, which closes the header block. - html("X-Content-Type-Options: nosniff\n"); - html("Content-Security-Policy: default-src 'none'\n"); + ctx.page.untrusted = 1; if (mimetype && is_unsafe_type(mimetype)) ctx.page.mimetype = NULL; } -- cgit v2.8.0