Use a content type that's not an XSS risk
authorTim Starling <tstarling@users.mediawiki.org>
Wed, 18 Mar 2009 20:20:10 +0000 (20:20 +0000)
committerTim Starling <tstarling@users.mediawiki.org>
Wed, 18 Mar 2009 20:20:10 +0000 (20:20 +0000)
includes/AjaxResponse.php

index 63468a1..de6b3c5 100644 (file)
@@ -45,7 +45,7 @@ class AjaxResponse {
                $this->mText = '';
                $this->mResponseCode = '200 OK';
                $this->mLastModified = false;
-               $this->mContentType= 'text/html; charset=utf-8';
+               $this->mContentType= 'application/x-wiki';
 
                if ( $text ) {
                        $this->addText( $text );