Send Permissions-Policy on every API response (closes #4)
check / check (push) Successful in 1m8s
check / check (push) Successful in 1m8s
docs/REPO_POLICIES.md requires a Permissions-Policy header restricting the browser features an application does not use. The API now denies the camera, microphone and location on every response, TestHeaders checks it, and the README's Design section names it. Model: opus-5-5
This commit is contained in:
+4
-1
@@ -151,7 +151,8 @@ func (h *handlers) respondError(w http.ResponseWriter, status int, sentence stri
|
||||
|
||||
// securityHeaders go on every response. The API returns JSON to
|
||||
// programs, so a browser may not frame, sniff, cache or refer from it,
|
||||
// and must reach it over HTTPS.
|
||||
// nor give it the camera, microphone or location, and must reach it
|
||||
// over HTTPS.
|
||||
func securityHeaders(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
header := w.Header()
|
||||
@@ -160,6 +161,8 @@ func securityHeaders(next http.Handler) http.Handler {
|
||||
"default-src 'none'; frame-ancestors 'none'")
|
||||
header.Set("X-Frame-Options", "DENY")
|
||||
header.Set("Referrer-Policy", "no-referrer")
|
||||
header.Set("Permissions-Policy",
|
||||
"camera=(), microphone=(), geolocation=()")
|
||||
header.Set("Strict-Transport-Security",
|
||||
"max-age=31536000; includeSubDomains")
|
||||
header.Set("Cache-Control", "no-store")
|
||||
|
||||
@@ -185,6 +185,7 @@ func TestHeaders(t *testing.T) {
|
||||
"Content-Security-Policy": "default-src 'none'; frame-ancestors 'none'",
|
||||
"X-Frame-Options": "DENY",
|
||||
"Referrer-Policy": "no-referrer",
|
||||
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
|
||||
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
|
||||
"Cache-Control": "no-store",
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user