Skip to content

fix(headers): add security response headers - #1157

Closed
mazzma12 wants to merge 1 commit into
mainfrom
fix/security-headers
Closed

mazzma12 wants to merge 1 commit into
mainfrom
fix/security-headers

Conversation

@mazzma12

Copy link
Copy Markdown
Contributor

Adds HSTS, X-Content-Type-Options, Referrer-Policy and X-Frame-Options to every response via customHttp.yml.
CSP left out: Matomo and tarteaucitron load third-party scripts, so it needs a report-only pass first.
After deploy, check that .md files and llms.txt still send X-Robots-Tag: noindex.

@aws-amplify-eu-west-1

Copy link
Copy Markdown

This pull request is automatically being deployed by Amplify Hosting (learn more).

Access this pull request here: https://pr-1157.d1to60jd2gb6y6.amplifyapp.com

@mazzma12

Copy link
Copy Markdown
Contributor Author

overkilled for a static website - won't do

@mazzma12 mazzma12 closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant