fix: keep public security headers authoritative

This commit is contained in:
2026-08-25 23:17:42 +08:00
parent 1fbfa32fbd
commit bfd84ccdb5
3 changed files with 14 additions and 2 deletions
+3
View File
@@ -39,6 +39,9 @@ func TestPublicPageNeedsNoSession(t *testing.T) {
if w.Code != http.StatusOK || w.Body.String() != "public app" {
t.Fatalf("status=%d body=%q", w.Code, w.Body.String())
}
if w.Header().Get("Cache-Control") != "no-store" || w.Header().Get("X-Frame-Options") != "DENY" {
t.Fatal("public application safety headers are missing")
}
}
func TestPublicAPIRejectsWrongOrigin(t *testing.T) {