You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助解决:MIME类型('application/json')不可执行导致的脚本执行拒绝问题

Fixing "Refused to execute script from '***' because its MIME type ('application/json') is not executable, and strict MIME type checking is enabled"

Hey there! Let's walk through why this error pops up and how to fix it properly.

First, let's break down the root cause: Modern browsers use strict MIME type checking to enforce security rules. When you try to load a resource as a script (via <script> tag), the browser expects the server to send it with an executable MIME type like text/javascript or application/javascript. If the server sends back application/json instead (a type meant for data, not executable code), the browser blocks it to prevent potential security risks.

Here are the most reliable fixes:

  • Stop treating JSON as a script file
    If you're trying to load a JSON file using a <script> tag, that's the core issue. JSON is raw data, not code meant to be executed. Instead, use fetch() or XMLHttpRequest to retrieve the JSON and process it in your existing JavaScript. For example:

    fetch('your-data.json')
      .then(response => response.json())
      .then(data => {
        // Work with your JSON data here
      });
    
  • Fix your server's MIME type configuration
    If the resource you're loading is actually a JavaScript file (not JSON), but your server is incorrectly labeling it as application/json, adjust your server settings to send the correct MIME type:

    • For Apache: Add this to your .htaccess file:
      AddType text/javascript .js
      
    • For Nginx: Update your server block with:
      types {
          text/javascript js;
      }
      
    • For Node.js/Express: When serving the script file, set the right Content-Type header:
      res.setHeader('Content-Type', 'text/javascript');
      res.sendFile('/path/to/your/script.js');
      
  • Skip disabling strict MIME checking (except for local debugging)
    While you can turn off strict MIME checking in your browser (like using Chrome's --disable-web-security flag), this is only a temporary workaround for local testing. Never do this in production—it exposes your app to major security vulnerabilities.

Content of the question comes from Stack Exchange, asked by Inderpreet Singh Saini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:10:09