flash9/10的安全策略之content-type

Flash Player 9安全策略更新
自Flash Player 9.0.115.0版本起,新增安全策略要求跨域策略文件crossdomain.xml的HTTP头必须包含Content-Type,并且其类型需为text/*、application/xml或application/xhtml+xml之一,以确保文件内容为文本格式。

flash9/10添加了新的安全策略.

请求的crossdomain.xml返回的http header必须包换content-type,而且必须是text/(任何文本格式)

如果不是这样的话,crossdomain.xml就算存在,也会被无视.

搞了一天才找出来,倒塌...

详情:http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security_02.html#_Content-Type_Whitelist

 

引用:

Content-type whitelist

Starting in version 9,0,115,0, Flash Player will ignore any HTTP policy file that is not sent with a Content-Type value that gives some assurance that the file is intended to be a text file. Flash Player requires that a policy file's Content-Type must be one of the following:

  • text/* (any text type)

  • application/xml or application/xhtml+xml

Content-Type values are determined from the response headers provided by HTTP servers. Servers may choose a Content-Type based on a file's name, extension, location, contents, or the instructions of a server script generating the file. If you need to change the Content-Type associated with a policy file, you may need to reconfigure a registry mapping filename extensions to Content-Type values, or edit a general server configuration file. Consult the documentation for your HTTP server.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值