A02: add security response headers to the web surface #10

Closed
opened 2026-08-13 09:35:03 +00:00 by nalum · 0 comments
Owner

The server sets no security headers anywhere (cmd/server/server.go:156-176, web/web.go:28-58), and the ingress adds none. The embedded app is served without CSP, HSTS, X-Content-Type-Options, or frame-ancestors protection.

The session JWT is safe from XSS because the cookie is httpOnly, but any future XSS in the React app runs with no CSP backstop, and the app can be framed.

Fix — a small middleware on the root mux:

  • Content-Security-Policy: default-src 'self' (fonts and scripts are bundled, so this is cheap)
  • Strict-Transport-Security on the public hostname
  • X-Content-Type-Options: nosniff
  • frame-ancestors 'none' (or X-Frame-Options: DENY)

Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

The server sets no security headers anywhere (`cmd/server/server.go:156-176`, `web/web.go:28-58`), and the ingress adds none. The embedded app is served without CSP, HSTS, `X-Content-Type-Options`, or frame-ancestors protection. The session JWT is safe from XSS because the cookie is httpOnly, but any future XSS in the React app runs with no CSP backstop, and the app can be framed. **Fix** — a small middleware on the root mux: - `Content-Security-Policy: default-src 'self'` (fonts and scripts are bundled, so this is cheap) - `Strict-Transport-Security` on the public hostname - `X-Content-Type-Options: nosniff` - `frame-ancestors 'none'` (or `X-Frame-Options: DENY`) --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:46 +00:00
nalum closed this issue 2026-08-13 11:38:59 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#10
No description provided.