Security headers baseline #23

Open
opened 2025-09-20 06:16:04 +00:00 by Nicholai · 0 comments
Owner

Summary: Add modern security headers.
Tasks:

  • Add CSP with allowlist for scripts, images, frames
  • Add HSTS, X-Content-Type-Options, Referrer-Policy, Frame-Options
  • Verify via securityheaders.com or similar
    Acceptance Criteria:
  • Headers present on all pages and scanner shows no critical issues
**Summary:** Add modern security headers. **Tasks:** - [ ] Add CSP with allowlist for scripts, images, frames - [ ] Add HSTS, X-Content-Type-Options, Referrer-Policy, Frame-Options - [ ] Verify via securityheaders.com or similar **Acceptance Criteria:** - [ ] Headers present on all pages and scanner shows no critical issues
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Nicholai/united-tattoo#23
No description provided.