middleware: add security response headers (closes #98)
check / check (push) Successful in 54s
check / check (push) Successful in 54s
Adds a SecurityHeaders middleware and registers it globally, right after the request ID middleware, so every route gets the headers, including static files, /metrics and error responses. It sets Strict-Transport-Security (one year, includeSubDomains), a Content-Security-Policy with default-src 'self', no scripts and frame-ancestors 'none', X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy no-referrer and a Permissions-Policy that turns every listed feature off. HSTS is sent on every response, not only over TLS: the service runs behind a TLS-terminating proxy and REPO_POLICIES.md requires the application to send it. Referrer-Policy is stricter than the policy baseline because dashboard URLs can name internal hosts. model: claude-opus-4-8 (implementation); claude-fable-5 (commit message)
This commit was merged in pull request #112.
This commit is contained in:
@@ -113,6 +113,16 @@ Rationale, Design, TODO, License, Author) if any are still missing.
|
||||
than the 60s `chimw.Timeout` handler budget so that budget stays
|
||||
reachable, and tests in `internal/server` pin both the non-zero
|
||||
values and that relationship (#99)
|
||||
- 2026-08-09: security response headers middleware
|
||||
(`SecurityHeaders()` in `internal/middleware/middleware.go`)
|
||||
registered globally in `internal/server/routes.go`, so HSTS, CSP,
|
||||
`X-Frame-Options`, `X-Content-Type-Options`, `Referrer-Policy`, and
|
||||
`Permissions-Policy` are set on every response including `/s/...` and
|
||||
`/metrics`; the CSP needs no `unsafe-inline`/`unsafe-eval` because the
|
||||
dashboard ships no JavaScript and no inline styles; HSTS is emitted
|
||||
unconditionally per policy (TLS-terminating proxy in front). Remaining
|
||||
1.0 hardening items — `http.Server` timeouts, request body limits,
|
||||
rate limiting, CORS scoping — are tracked separately
|
||||
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
|
||||
in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the
|
||||
org-standard v2-schema config used across the org's repos
|
||||
|
||||
Reference in New Issue
Block a user