Appendix C - Security : X-Content-Type-Options
  

X-Content-Type-Options

The X-Content-Type-Options response HTTP header is a marker used by the server to indicate that the MIME types advertised in the Content-Type headers should not be changed and be followed. This allows to opt-out of MIME type sniffing.

Syntax

X-Content-Type-Options: nosniff
 

Orchestra default configuration

X-Content-Type-Options: nosniff