Send Permissions-Policy on every API response (closes #4)
check / check (push) Successful in 1m8s

docs/REPO_POLICIES.md requires a Permissions-Policy header restricting
the browser features an application does not use. The API now denies
the camera, microphone and location on every response, TestHeaders
checks it, and the README's Design section names it.

Model: opus-5-5
This commit is contained in:
clawbot
2026-09-29 00:59:42 +00:00
parent 17d6be9fe1
commit b965e45454
3 changed files with 8 additions and 3 deletions
+4 -1
View File
@@ -151,7 +151,8 @@ func (h *handlers) respondError(w http.ResponseWriter, status int, sentence stri
// securityHeaders go on every response. The API returns JSON to
// programs, so a browser may not frame, sniff, cache or refer from it,
// and must reach it over HTTPS.
// nor give it the camera, microphone or location, and must reach it
// over HTTPS.
func securityHeaders(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
header := w.Header()
@@ -160,6 +161,8 @@ func securityHeaders(next http.Handler) http.Handler {
"default-src 'none'; frame-ancestors 'none'")
header.Set("X-Frame-Options", "DENY")
header.Set("Referrer-Policy", "no-referrer")
header.Set("Permissions-Policy",
"camera=(), microphone=(), geolocation=()")
header.Set("Strict-Transport-Security",
"max-age=31536000; includeSubDomains")
header.Set("Cache-Control", "no-store")
+1
View File
@@ -185,6 +185,7 @@ func TestHeaders(t *testing.T) {
"Content-Security-Policy": "default-src 'none'; frame-ancestors 'none'",
"X-Frame-Options": "DENY",
"Referrer-Policy": "no-referrer",
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
"Cache-Control": "no-store",
}