StrictMimetypeCheckForWorkerScriptsEnabled

Enable strict MIME type checking for worker scripts

Supported on:

  • Chrome (Windows) since version 107

Description:

This policy enables strict MIME type checking for worker scripts.

When enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected.

When disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed.

Browsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired.

See https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.

true = Scripts for workers (Web Workers, Service Workers, etc.) require a JavaScript MIME type, like text/javascript. Worker scripts with legacy MIME types, like text/ascii, will be rejected.
false = Scripts for workers (Web Workers, Service Workers, etc.) use lax MIME type checking. Worker scripts with legacy MIME types, like text/ascii, will work.

Supported features:

  • Applied to browser without restart. Note that some ongoing tasks may not be affected.
  • Applied at Samsung Browser profile level.

Data type:

Boolean
Windows:REG_DWORD

Windows registry location:

Software\Policies\Samsung\Internet\StrictMimetypeCheckForWorkerScriptsEnabled

Example value:

0x00000000

More policies under Miscellaneous: