Glossary Term
MIME Type (Media Type)
A MIME type, or media type, is the type/subtype label in Content-Type that tells clients how to interpret a body. Covers nosniff and blocked-script errors.
TL;DR: A MIME type (officially a media type) is the
type/subtypelabel in theContent-Typeheader, such astext/htmlorapplication/json. Browsers trust it more than the file extension.
A MIME type, called a media type in RFC 9110, is a two-part identifier of the form type/subtype, optionally followed by parameters, that tells the receiver how to interpret a message body. It is carried in Content-Type on responses and on requests with bodies, and the registry of valid values is maintained by IANA.
Anatomy
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-Content-Type-Options: nosniff
textis the top-level type;htmlis the subtype;charset=utf-8is a parameter.- Suffixes such as
application/ld+jsonandimage/svg+xmlmean “this is JSON-LD” and “this is XML-based”. application/jsondefines nocharsetparameter, because JSON is always UTF-8.
The errors this causes
With nosniff set, Chrome refuses wrongly typed scripts and stylesheets:
Refused to execute script from 'https://example.com/app.js' because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled.
Failed to load module script: Expected a JavaScript module script but the server responded with a MIME type of "text/html". Strict MIME type checking is enforced for module scripts per HTML spec.
Module scripts are checked even without nosniff. In both cases the actual cause is almost always a 404 that the server replaced with index.html, often after a deploy removed an old hashed asset.
Non-obvious facts
- Browsers sniff when the type is missing or wrong, which is why
X-Content-Type-Options: nosniffexists. It also prevents a user-uploaded file from being interpreted as HTML or script. text/plainis not a safe default for uploads. Serve user content with an explicit type andContent-Disposition: attachmentwhere possible.- Requests have media types too. Sending JSON with
Content-Type: text/plainor form encoding to a JSON parser yields a 415 Unsupported Media Type or an empty body in frameworks like Express. - The
Acceptheader is the other half. The client lists types it can handle; the server picks one and labels it inContent-Type.
Go deeper
Frequently asked questions
What is the difference between a MIME type and a media type?
They are the same thing. RFC 9110 calls it a media type; MIME type is the older name from email, and both appear in the Content-Type header.
What is the MIME type for JSON and JavaScript?
application/json for JSON, and text/javascript for JavaScript. HTML specifies text/javascript as the one to use; application/javascript is obsolete but still recognized.
What does "strict MIME type checking is enabled" mean?
The response has X-Content-Type-Options: nosniff, so the browser refuses to run a script or apply a stylesheet whose Content-Type is not a JavaScript or CSS type.
Why does my missing JavaScript file return text/html?
A single-page app fallback rule is serving index.html for every unknown path, including a missing chunk. The browser then rejects the HTML as a script.
Sources
Related
Accept Header
Learn how the Accept header tells servers which content types (JSON, HTML, XML) your client can handle. Master content negotiation and quality values.
Content-Type Header: Values, Examples, charset
Content-Type tells the receiver what the body is: application/json, text/html; charset=utf-8, multipart/form-data. Common values, examples and 415 fixes.
X-Content-Type-Options Header
Learn how X-Content-Type-Options with nosniff prevents browsers from MIME-sniffing responses. Protect against XSS attacks from content type confusion.
415 Unsupported Media Type
415 Unsupported Media Type: the server won't accept your Content-Type. Real Spring, DRF and ASP.NET errors, curl reproduction, fixes for fetch and FormData.