ithelloworld asked 6 months ago

When you browse the Web site with Chrome and execute a javascript, the following errors occur:

Refused to execute script from 'http://mysite.com/info?no=31&magic=9543' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.

Other browsers, such as Firefox, are fine.
A simple way to learn from Stack Overflow is to set up HTTP header X-XSS-Protection:

X-XSS-Protection: 0

Is this the best solution?

Pymaster replied 6 months ago

I think your question is slightly different from that in Stack Overflow, but similar to the following one:http://stackoverflow.com/questions/17341122/link-and-execute-external-javascript-file-hosted-on-githubThe main reason is<script>The MIME type settings for content are not executable scripts (for example:text/javascript)。

ithelloworld answered 6 months ago

The solution is to change the text/html of MIME type to application/x-javascript