Hacker News new | ask | show | jobs
by mfa 1649 days ago
Got it. Makes sense and just added it. You can now curl https://www.pastesafely.com/pastes/P73?format=raw ;-)
2 comments

Let me put all suggestions on this together. They should be fairly easy to implement and will enhance the usefulness and security of this feature:

* You should support HTTP HEAD request

* You should infer MIME type from language selections and set Content-Type header as much as possible. If there is none, the default shall be text/plain not text/html

* You should set `Content-Security-Policy: sandbox` HTTP header so people cannot use your service to do malicious stuff

* You should set `Access-Control-Allow-Origin: *` so it can be used in pure client-side JAMStack applications

Thanks. If you can infer the correct MIME type from the language and send the correct Content-Type header it will be even more useful. I know most languages don't have a dedicated MIME, but some do, such as html, json or svg.
I think all you're suggestions are good and just finished adding them. Thanks for the feedback!