Send Permissions-Policy on every API response (closes #4)
check / check (push) Successful in 1m8s
check / check (push) Successful in 1m8s
docs/REPO_POLICIES.md requires a Permissions-Policy header restricting the browser features an application does not use. The API now denies the camera, microphone and location on every response, TestHeaders checks it, and the README's Design section names it. Model: opus-5-5
This commit is contained in:
@@ -185,6 +185,7 @@ func TestHeaders(t *testing.T) {
|
||||
"Content-Security-Policy": "default-src 'none'; frame-ancestors 'none'",
|
||||
"X-Frame-Options": "DENY",
|
||||
"Referrer-Policy": "no-referrer",
|
||||
"Permissions-Policy": "camera=(), microphone=(), geolocation=()",
|
||||
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
|
||||
"Cache-Control": "no-store",
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user