请求协助解决:MIME类型('application/json')不可执行导致的脚本执行拒绝问题
Hey there! Let's walk through why this error pops up and how to fix it properly.
First, let's break down the root cause: Modern browsers use strict MIME type checking to enforce security rules. When you try to load a resource as a script (via <script> tag), the browser expects the server to send it with an executable MIME type like text/javascript or application/javascript. If the server sends back application/json instead (a type meant for data, not executable code), the browser blocks it to prevent potential security risks.
Here are the most reliable fixes:
Stop treating JSON as a script file
If you're trying to load a JSON file using a<script>tag, that's the core issue. JSON is raw data, not code meant to be executed. Instead, usefetch()orXMLHttpRequestto retrieve the JSON and process it in your existing JavaScript. For example:fetch('your-data.json') .then(response => response.json()) .then(data => { // Work with your JSON data here });Fix your server's MIME type configuration
If the resource you're loading is actually a JavaScript file (not JSON), but your server is incorrectly labeling it asapplication/json, adjust your server settings to send the correct MIME type:- For Apache: Add this to your
.htaccessfile:AddType text/javascript .js - For Nginx: Update your server block with:
types { text/javascript js; } - For Node.js/Express: When serving the script file, set the right Content-Type header:
res.setHeader('Content-Type', 'text/javascript'); res.sendFile('/path/to/your/script.js');
- For Apache: Add this to your
Skip disabling strict MIME checking (except for local debugging)
While you can turn off strict MIME checking in your browser (like using Chrome's--disable-web-securityflag), this is only a temporary workaround for local testing. Never do this in production—it exposes your app to major security vulnerabilities.
Content of the question comes from Stack Exchange, asked by Inderpreet Singh Saini

