Send Permissions-Policy on every API response (closes #4)
check / check (push) Successful in 1m8s

docs/REPO_POLICIES.md requires a Permissions-Policy header restricting
the browser features an application does not use. The API now denies
the camera, microphone and location on every response, TestHeaders
checks it, and the README's Design section names it.

Model: opus-5-5
This commit is contained in:
clawbot
2026-09-29 00:59:42 +00:00
parent 17d6be9fe1
commit b965e45454
3 changed files with 8 additions and 3 deletions
+3 -2
View File
@@ -222,8 +222,9 @@ container.
starts once set-up is done; if it cannot listen, the bot exits with an
error, as when the chat client fails. Every request must carry the
credential, compared in constant time; every response carries headers
that forbid framing, content sniffing, caching and referrers; a
request body is capped at 64 KiB and a request's work at 10 seconds.
that forbid framing, content sniffing, caching and referrers, and a
`Permissions-Policy` that denies the camera, microphone and location;
a request body is capped at 64 KiB and a request's work at 10 seconds.
Handlers call the chat client on the request's own goroutine, never on
the one that delivers events, which also delivers the chat client's
answers. When the bot stops, requests in progress get 5 seconds to