Skip to content

fix(security): preserve the complete Helmet CSP - #186

Merged
ttbombadil merged 1 commit into
mainfrom
fix/csp-effective-header
Oct 4, 2026
Merged

ttbombadil merged 1 commit into
mainfrom
fix/csp-effective-header

Conversation

@ttbombadil

Copy link
Copy Markdown
Collaborator

Summary

  • Keep Helmet as the sole owner of the complete Content-Security-Policy.
  • Remove the later frame-ancestors-only overwrite; retain the existing policy and embedding allowlist.
  • Add a regression test against final HTTP responses from the actual server launcher, including an early 404 and deduplicated configured frame ancestors.

Evidence

Base: 2b9facf13b9578717fce4081005d04cba5c47133 from freshly fetched origin/main.

RED: the new HTTP test failed because default-src was absent from the final header.
GREEN: all four development-entrypoint tests pass after the minimal removal.

Verification

  • Supported Node 24.20.0; fresh npm ci.
  • Type checks, docs check, application build, and ESLint without automatic fixing passed (existing warnings only).
  • Full unit/coverage suite passed; local Sonar quality gate passed.
  • Real toolchain integration: 14 passed, 1 skipped.
  • Docker integration: 27 passed.
  • Full Chromium E2E: 25 passed, no retries/race-condition events.
  • Independent read-only review found no issues.
  • Normal commit/pre-push hooks retained.

No Provider calls, SSOT changes, Tutor/didactic changes, or edits to existing local untracked/protected documents.

@ttbombadil
ttbombadil merged commit 221b83b into main Oct 4, 2026
5 checks passed
@ttbombadil
ttbombadil deleted the fix/csp-effective-header branch October 5, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant