Author: benjamin
Description:
action=raw allows ctype=text/javascript by default. This is not a good security
setting, because it becomes very easy for wikipages to link to this script and
steal login cookies and other important cookie data.
This patch adds a configurable whitelist of allowed mimetypes and also a
configurable default mimetype.
Version: 1.4.x
Severity: enhancement