Altinn / altinn-access-management-frontend

Frontend for access management
MIT License
3 stars 1 forks source link

Set security headers and coors #347

Closed TheTechArch closed 4 weeks ago

TheTechArch commented 1 year ago

Description

We need to set the recomended security headers in BFF See https://github.com/Altinn/app-lib-dotnet/blob/main/src/Altinn.App.Api/Infrastructure/Middleware/SecurityHeadersMiddleware.cs

Additional Information

No response

Tasks

Acceptance Criteria

jonkjetiloye commented 1 year ago

Verified response headers are now set: referer-policy: no-referer x-content-type-options: nosniff x-frame-options: deny x-xss-protection: 0

sivaglen commented 1 year ago

@jonkjetiloye - betyr det at denne kan lukkes?

jonkjetiloye commented 1 year ago

@sivaglen har da bare fått verifisert at security headers er satt. @TheTechArch hvordan får vi ellers sjekket cors/XSRF?