Skip to content

feat(servicehttp): send nosniff and frame-deny from the Go services - #254

Merged
jdwillmsen merged 2 commits into
mainfrom
feat/JDWLABS-659-security-headers-bot
Oct 1, 2026
Merged

jdwillmsen merged 2 commits into
mainfrom
feat/JDWLABS-659-security-headers-bot

Conversation

@jdwlabs-agent-bot

@jdwlabs-agent-bot jdwlabs-agent-bot Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Why

The JVM sends X-Content-Type-Options: nosniff and X-Frame-Options: DENY on every response; the Go identity-service and profile-service sent neither, so each path group cut over would lose them. JDWLABS-659.

Needs attention

  • libs/backend/shared/servicehttp/headers.go:13 — new SecurityHeaders middleware; only these two headers, deliberately no HSTS or Cache-Control.
  • apps/backend/identity-service/server.go:120, apps/backend/profile-service/server.go:112 — wrapped outermost, outside CORS (as the JVM does), so 401, 403 and health responses carry the headers. Is that order right?

Risk / rollout

Merging releases identity-service and profile-service. non picks the build up only after deployments #280 merges.

Verified

  • go test ./libs/backend/shared/servicehttp/ ./apps/backend/identity-service/ ./apps/backend/profile-service/ — pass (2xx, 401, 404, refused origin, health)
  • Earlier run: real binaries over curl showed both headers on 200, 401, 403 and preflight; old server.go wiring fails the new tests
  • Prettier/CI format check not run locally

jdwillmsen
jdwillmsen previously approved these changes Oct 1, 2026

@jdwillmsen jdwillmsen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by an agent at the owner's instruction after a line-by-line pre-merge review: checks green, headers set outermost so error responses carry them, tests cover 2xx/401/404/403/health, no new alerts.

The JVM's HeaderWriterFilter puts X-Content-Type-Options: nosniff and
X-Frame-Options: DENY on every response; identity-service and
profile-service sent neither, so every path group cut over to Go lost
them. Add a shared SecurityHeaders middleware to servicehttp and wrap
both servers with it outermost, setting the headers before any inner
layer writes so 401, 403 (CORS), 404 and health responses carry them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: Claude Code:claude-opus-5-5
@jdwlabs-agent-bot jdwlabs-agent-bot Bot closed this Oct 1, 2026
@jdwlabs-agent-bot
jdwlabs-agent-bot Bot force-pushed the feat/JDWLABS-659-security-headers-bot branch from 2931e4b to df1c1c9 Compare October 1, 2026 07:06
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assisted-by: Claude Code:claude-opus-5-5

@jdwillmsen jdwillmsen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-approved by an agent at the owner's instruction after rebasing onto current main (content unchanged); checks green, no new alerts.

@jdwillmsen
jdwillmsen merged commit dc89d40 into main Oct 1, 2026
22 checks passed
@jdwillmsen
jdwillmsen deleted the feat/JDWLABS-659-security-headers-bot branch October 1, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant