public class

XContentTypeOptionsNoSniffFilter

extends AbstractHttpFilter
java.lang.Object
   ↳ com.atlassian.core.filters.AbstractHttpFilter
     ↳ com.atlassian.jira.web.filters.XContentTypeOptionsNoSniffFilter

Class Overview

This exists solely to deal with a security vulnerability in Internet Explorer: JRA-28879 IE can be tricked into parsing a text/html page as a stylesheet if it contains certain characters. Hence, a JIRA page can be loaded as a stylesheet on an external, malicious site and voila, XSS.

Summary

Public Constructors
XContentTypeOptionsNoSniffFilter()
Public Methods
void doFilter(HttpServletRequest req, HttpServletResponse resp, FilterChain chain)
[Expand]
Inherited Methods
From class com.atlassian.core.filters.AbstractHttpFilter
From class java.lang.Object
From interface javax.servlet.Filter

Public Constructors

public XContentTypeOptionsNoSniffFilter ()

Public Methods

public void doFilter (HttpServletRequest req, HttpServletResponse resp, FilterChain chain)

Throws
IOException
ServletException