fix(server): add security response headers #23
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!23
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/security-headers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds a
WithSecurityHeadersmiddleware around the root mux, so the SPA,/docs, and the RPC surface all carry:Content-Security-Policy: default-src 'self'; img-src 'self' data:; font-src 'self' data:; connect-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'— nounsafe-inlineanywhere: the built bundle has no inline styles or scripts (verified against a realnpm run buildoutput).data:for fonts/images is required because Vite inlines small @fontsource subsets.Strict-Transport-Security: max-age=31536000(noincludeSubDomains— sibling subdomains exist on the household domain)X-Content-Type-Options: nosniff,X-Frame-Options: DENY,Referrer-Policy: no-referrerUnit test asserts every header and that no
unsafe-*expression appears in the CSP.Fixes #10
🤖 Generated with Claude Code
5bf7ddefa82f8f843ab2