diff --git a/docker-compose.yml b/docker-compose.yml index 684dce9..5ff5a01 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,7 +5,7 @@ services: build: context: . args: - VERSION: v2026.08.25-r4 + VERSION: v2026.08.25-r5 restart: unless-stopped ports: - "127.0.0.1:8083:8080" diff --git a/public_server.go b/public_server.go index 9791986..2724e47 100644 --- a/public_server.go +++ b/public_server.go @@ -72,7 +72,16 @@ func (a *publicApp) routes() http.Handler { mux.HandleFunc("GET /health", func(w http.ResponseWriter, _ *http.Request) { writeJSON(w, http.StatusOK, map[string]string{"status": "ok"}) }) - return a.core.securityHeaders(mux) + return a.securityHeaders(mux) +} + +func (a *publicApp) securityHeaders(next http.Handler) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + w.Header().Set("Cache-Control", "no-store") + w.Header().Set("Cross-Origin-Opener-Policy", "same-origin") + w.Header().Set("X-Frame-Options", "DENY") + next.ServeHTTP(w, r) + }) } func (a *publicApp) index(w http.ResponseWriter, r *http.Request) { diff --git a/public_server_test.go b/public_server_test.go index dda416d..cabb4f1 100644 --- a/public_server_test.go +++ b/public_server_test.go @@ -39,6 +39,9 @@ func TestPublicPageNeedsNoSession(t *testing.T) { if w.Code != http.StatusOK || w.Body.String() != "public app" { t.Fatalf("status=%d body=%q", w.Code, w.Body.String()) } + if w.Header().Get("Cache-Control") != "no-store" || w.Header().Get("X-Frame-Options") != "DENY" { + t.Fatal("public application safety headers are missing") + } } func TestPublicAPIRejectsWrongOrigin(t *testing.T) {