And fix magic numbers for content-type sniffing, which wrongly used the Unicode replacement character (which likely just meant we were falling back to file-extension-based detection)