Skip to content

Conversation

@gary149
Copy link
Collaborator

@gary149 gary149 commented Nov 24, 2025

Introduces comprehensive security headers and forces 'text/plain' content type for all responses from the fetch-url API endpoint. This prevents execution of active content and mitigates risks if the endpoint is accessed directly.

Introduces comprehensive security headers and forces 'text/plain' content type for all responses from the fetch-url API endpoint. This prevents execution of active content and mitigates risks if the endpoint is accessed directly.
@gary149 gary149 requested a review from coyotte508 November 24, 2025 13:06
@coyotte508
Copy link
Member

does it break anything?

@gary149
Copy link
Collaborator Author

gary149 commented Nov 24, 2025

does it break anything?

Yes probably the flow where you want to fetch an image from it (and some other types but that's probably fine for now)

@gary149 gary149 merged commit 86f0810 into main Nov 24, 2025
4 of 6 checks passed
@gary149 gary149 deleted the url-fetch-strong-csp-header-and-plain-text branch November 24, 2025 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants