Repository navigation
feat(servicehttp): send nosniff and frame-deny from the Go services - #254
Merged
Merged
Conversation
jdwlabs-agent-bot
Bot
force-pushed
the
feat/JDWLABS-659-security-headers-bot
branch
from
October 1, 2026 04:07
7b5c36e to
0a5e007
Compare
jdwillmsen
previously approved these changes
Oct 1, 2026
jdwillmsen
left a comment
Member
There was a problem hiding this comment.
Approved by an agent at the owner's instruction after a line-by-line pre-merge review: checks green, headers set outermost so error responses carry them, tests cover 2xx/401/404/403/health, no new alerts.
The JVM's HeaderWriterFilter puts X-Content-Type-Options: nosniff and X-Frame-Options: DENY on every response; identity-service and profile-service sent neither, so every path group cut over to Go lost them. Add a shared SecurityHeaders middleware to servicehttp and wrap both servers with it outermost, setting the headers before any inner layer writes so 401, 403 (CORS), 404 and health responses carry them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: Claude Code:claude-opus-5-5
jdwlabs-agent-bot
Bot
force-pushed
the
feat/JDWLABS-659-security-headers-bot
branch
from
October 1, 2026 07:06
2931e4b to
df1c1c9
Compare
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assisted-by: Claude Code:claude-opus-5-5
jdwillmsen
approved these changes
Oct 1, 2026
jdwillmsen
left a comment
Member
There was a problem hiding this comment.
Re-approved by an agent at the owner's instruction after rebasing onto current main (content unchanged); checks green, no new alerts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The JVM sends
X-Content-Type-Options: nosniffandX-Frame-Options: DENYon every response; the Go identity-service and profile-service sent neither, so each path group cut over would lose them. JDWLABS-659.Needs attention
libs/backend/shared/servicehttp/headers.go:13— newSecurityHeadersmiddleware; only these two headers, deliberately no HSTS or Cache-Control.apps/backend/identity-service/server.go:120,apps/backend/profile-service/server.go:112— wrapped outermost, outside CORS (as the JVM does), so 401, 403 and health responses carry the headers. Is that order right?Risk / rollout
Merging releases identity-service and profile-service. non picks the build up only after deployments #280 merges.
Verified
go test ./libs/backend/shared/servicehttp/ ./apps/backend/identity-service/ ./apps/backend/profile-service/— pass (2xx, 401, 404, refused origin, health)server.gowiring fails the new tests