Skip to content

Conversation

@whpearson
Copy link
Contributor

This adds the headers

X-Content-Type-Options: X-Content-Type-Options: nosniff

Strict-Transport-Security: Strict-Transport-Security: max-age=31536000; includeSubDomains

Cache-control: Cache-control: no-store / Pragma: no-cache

X-Frame-Options: X-Frame-Options: DENY / X-Frame-Options: SAMEORIGIN

X-Permitted-Cross-Domain-Policies: X-Permitted-Cross-Domain-Policies: none

It removes

X-Xss-Protection: 1; mode=block

I've checked it locally for email branding in safari, firefox and chome.

This adds the headers

X-Content-Type-Options: X-Content-Type-Options: nosniff

Strict-Transport-Security: Strict-Transport-Security: max-age=31536000; includeSubDomains

Cache-control: Cache-control: no-store / Pragma: no-cache

X-Frame-Options: X-Frame-Options: DENY / X-Frame-Options: SAMEORIGIN

X-Permitted-Cross-Domain-Policies: X-Permitted-Cross-Domain-Policies: none

It removes

X-Xss-Protection: 1; mode=block
@whpearson whpearson force-pushed the add_security_headers branch from 4dd0149 to ea4abb4 Compare January 28, 2026 14:05
@kr8n3r
Copy link
Contributor

kr8n3r commented Jan 29, 2026

most things work as expected. I do get an error previewing newly created letter branding, but that could just be notifications-local having an issue.
ideally, this PR, document-download, api and any others would all together be deployed to a dev env for a complete cross apps test in a near-prod scenario

@whpearson
Copy link
Contributor Author

Okay, I'll work on that today. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants