Skip to main content

April 20, 2026

Content Type Checking

By default, Horizon accepts requests with the following declared content types only:

  • application/x-www-form-urlencoded
  • application/xml
  • text/xml

Note: In earlier releases, this protection was disabled by default.

To restrict the content types that Horizon accepts, add the following entry to the file locked.properties:

acceptContentType.1=content-type

For example:

acceptContentType.1=x-www-form-urlencoded

To accept another content type, add the entry acceptContentType.2=content-type, and so on

To accept requests with any declared content type, specify acceptContentType=*.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…