-
Notifications
You must be signed in to change notification settings - Fork 21
chore: replace security-header-lambda with native cloudfront responseheaderpolicy #11628
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
chore: replace security-header-lambda with native cloudfront responseheaderpolicy #11628
Conversation
🎉 Snyk checks have passed. No issues have been found so far.✅ security/snyk check is complete. No issues have been found. (View Details) ✅ license/snyk check is complete. No issues have been found. (View Details) ✅ code/snyk check is complete. No issues have been found. (View Details) |
|
Feel free to tell me where to go 😅 should we make it consistent, like you have or make it a construct to future proof it. Sorry in advance |
| ResponseHeadersPolicy, | ||
| } from 'aws-cdk-lib/aws-cloudfront' | ||
|
|
||
| const defaultContentSecurityPolicy = |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
These differ between dev and prod. Is this catered for here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
it's purposefully not, there shouldn't be any difference in config between prod and dev
plittlewood-rpt
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you let me know about dev/prod difference (see comment) before we merge this.
…f-security-header-lambda
needs testing on dev
unit test fail is due to cognito-custom-mailer coverage so unrelated