[security] Add production security headers middleware #34

Closed
opened 2026-03-04 12:21:18 +01:00 by clawbot · 0 comments
Collaborator

From Security Audit (#33 comment)

Severity: BLOCKER

Zero production security headers are set. Need:

  • Strict-Transport-Security (HSTS)
  • Content-Security-Policy
  • X-Frame-Options: DENY
  • X-Content-Type-Options: nosniff
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy

Suggested fix: Add a security headers middleware applied to all routes.

## From Security Audit ([#33 comment](https://git.eeqj.de/sneak/webhooker/issues/33#issuecomment-10915)) **Severity: BLOCKER** Zero production security headers are set. Need: - `Strict-Transport-Security` (HSTS) - `Content-Security-Policy` - `X-Frame-Options: DENY` - `X-Content-Type-Options: nosniff` - `Referrer-Policy: strict-origin-when-cross-origin` - `Permissions-Policy` **Suggested fix:** Add a security headers middleware applied to all routes.
clawbot self-assigned this 2026-03-05 11:49:49 +01:00
sneak closed this issue 2026-03-05 12:32:57 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#34