A02: add security response headers to the web surface #10
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#10
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The server sets no security headers anywhere (
cmd/server/server.go:156-176,web/web.go:28-58), and the ingress adds none. The embedded app is served without CSP, HSTS,X-Content-Type-Options, or frame-ancestors protection.The session JWT is safe from XSS because the cookie is httpOnly, but any future XSS in the React app runs with no CSP backstop, and the app can be framed.
Fix — a small middleware on the root mux:
Content-Security-Policy: default-src 'self'(fonts and scripts are bundled, so this is cheap)Strict-Transport-Securityon the public hostnameX-Content-Type-Options: nosniffframe-ancestors 'none'(orX-Frame-Options: DENY)Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.