Skip to content

Missing Security Headers #17

@kasimlyee

Description

@kasimlyee

Problem: No security headers injected automatically:

  • No Content-Security-Policy
  • No X-Frame-Options
  • No X-Content-Type-Options
  • No Strict-Transport-Security
  • No Referrer-Policy

Impact: High - XSS, clickjacking, MIME sniffing attacks
Fix: Creating SecurityHeadersMiddleware

Metadata

Metadata

Labels

great findingone of the eye opening finds everhelp wantedExtra attention is needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions