application/zip
application/zip is the registered type for ZIP archives. It looks simple, but uploads arrive under several names, and many other file formats are ZIP archives inside.
Header
Content-Type: application/zipAt a glance
- Extensions
- .zip
- Kind
- Binary
- Parameters
- None
- In a browser
- Downloads the file.
With curl
curl -o export.zip -H 'Accept: application/zip' https://api.example.com/exports/42
With fetch
const res = await fetch('https://api.example.com/exports/42', { headers: { Accept: 'application/zip' } });
const blob = await res.blob();Common mistakes
Uploads arrive under other names
Browsers on Windows often label ZIP uploads
application/x-zip-compressed, and some sendapplication/octet-stream. Accept those too, and check the first bytes of the file (PK\x03\x04).Office files are ZIPs
.docx,.xlsx,.pptxand.jarfiles are ZIP archives with types of their own, and their first bytes cannot tell them apart. EPUB and OpenDocument files can be told apart: they store an uncompressedmimetypeentry first.Zip bombs and paths
A small archive can unpack to gigabytes, and an entry named
../../etc/passwdcan write outside the target folder (Zip Slip). Limit the unpacked size and reject entries whose path leaves the folder.