We use cookies to give you the best experience on our website. If you continue to browse, then you agree to our privacy policy and cookie policy. Image for the cookie policy date
close icon

Images and drop down boxes are not populating after configuring X-Content-Type-Options: nosniff response header

Hi Team,

For the security purpose we have configured the web server to always send the X-Content-Type-Options: nosniff specification in the response headers. But images and drop down boxes are not populating after configuring this header. 

Please find the attached screenshots which would explain the issue clearly.

Could you please help us on how to fix this issue when X-Content-Type-Options: nosniff is configured?

Thank you,

Sandeep


Attachment: screenshots_cb3d031d.zip

5 Replies

RG Ramesh Govindaraj Syncfusion Team August 31, 2016 11:02 AM UTC

Hi Sandeep, 

Thank you for using Syncfusion products. 

The statement “X-Content-Type-Options: nosniff” in web.config file doesn’t consider MIME type info while deploying the sample which results some of the images/icons not displayed. This is happened only in Internet Explorer. Please find the following links which shows the conversation regarding the reported problem. 


So, kindly replace the above mentioned statement with any other alternative option to improve the security. 

Regards,
Ramesh G. 



SA Sandeep August 31, 2016 03:50 PM UTC

Hi Ramesh,

Thanks for your reply.

There is no alternatives for this security fix.

The issue is image type and the extension are not matching, so IE browser is not populating the images. Could you please review this from your end that why these images have mismatch?

Thank you, 
Sandeep 


RG Ramesh Govindaraj Syncfusion Team September 1, 2016 08:09 AM UTC

Hi Sandeep, 

We have raised your query in “Stack Overflow” and “MSDN” to get a solution for the reported problem. Please find the below links where you can trace the query to get the solution. 



Regards,
Ramesh G. 
 



SA Sandeep September 14, 2016 10:29 AM UTC

Hi Ramesh,

It's a known issue that when the image type and extension are not matching then IE browser will not populate that image. So please check why these images have mismatch.

An could you please follow up with the query in “Stack Overflow” and “MSDN” ?

Thanks,
Sandeep


RG Ramesh Govindaraj Syncfusion Team September 15, 2016 04:54 AM UTC

Hi Sandeep, 

We have added your query in both “Stack Overflow” and “MSDN”. Additionally we have raised the entire query in “ASP.NET” forum which was suggested from “MSDN”. Please find the below link to track “ASP.NET” forum. 
 

Regards,
Ramesh G. 
 


Loader.
Live Chat Icon For mobile
Up arrow icon