From 3c98b7a5ad1bb596a738e550fc3bf966d6415fe0 Mon Sep 17 00:00:00 2001 From: Petr Skoda Date: Thu, 30 Oct 2014 11:16:26 +1300 Subject: [PATCH] MDL-47966 Add default content type and encoding --- lib/setup.php | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/lib/setup.php b/lib/setup.php index 5ba6be0b263..9c93a42e673 100644 --- a/lib/setup.php +++ b/lib/setup.php @@ -772,6 +772,24 @@ if (empty($CFG->sessiontimeout)) { } \core\session\manager::start(); +// Set default content type and encoding, developers are still required to use +// echo $OUTPUT->header() everywhere, anything that gets set later should override these headers. +// This is intended to mitigate some security problems. +if (AJAX_SCRIPT) { + if (!core_useragent::supports_json_contenttype()) { + // Some bloody old IE. + @header('Content-type: text/plain; charset=utf-8'); + @header('X-Content-Type-Options: nosniff'); + } else if (!empty($_FILES)) { + // Some ajax code may have problems with json and file uploads. + @header('Content-type: text/plain; charset=utf-8'); + } else { + @header('Content-type: application/json; charset=utf-8'); + } +} else if (!CLI_SCRIPT) { + @header('Content-type: text/html; charset=utf-8'); +} + // Initialise some variables that are supposed to be set in config.php only. if (!isset($CFG->filelifetime)) { $CFG->filelifetime = 60*60*6;