{"version":"2.1.295","anchor":"mcp-preview-server-adds-nosniff-and-headers","canonical_anchor":"mcp-preview-server-adds-nosniff-and-headers","heading":"Local preview server tells browsers not to guess file types","tier":"notice","area":"MCP","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/mcp-preview-server-adds-nosniff-and-headers","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Local preview server tells browsers not to guess file types\n\nThe local MCP preview server now sends a nosniff header and applies its shared set of headers to more of its responses\n\n**What**\n\nThe local preview server for MCP (Model Context Protocol, a way to connect external tools to Claude Code) now sends `x-content-type-options: nosniff` with its responses. This header tells the browser to trust the declared file type instead of guessing it.\n\nThe server's shared set of headers is now also applied to its \"not found\" response and to responses that are not web pages.\n\n**Why**\n\nThis is a small security hardening of the preview server. A browser can no longer be led to treat a file as a different kind of content than the server said it was.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}