As was pointed out in a cousin comment, it's not necessarily the browser or the webserver configuration.
SSL proxies -- corporate middleware -- have a habit of breaking this way, by stripping the content-disposition field or similar.
SSL proxies -- corporate middleware -- have a habit of breaking this way, by stripping the content-disposition field or similar.
If that's really happening (I have my doubts) and that's a client you want to continue supporting, then the next step would be limiting yourself to SingleFileZ-style ZIP payloads that can be as text/html.