Add default headers to webserver responses #97784
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Breaking change
Home Assistant can't be put in an iframe anymore by default. If you still want to embed the Home Assistant interface in a frame, you can do so by disabling
use_x_frame_options
by setting it tofalse
in thehttp
configuration.Proposed change
This PR adds a little bit of middleware, that sets some useful headers by default. To improve both security and privacy.
Referrer-Policy
to disable any referrer to be sent out. This prevents leaking your instance URL when navigating away.X-Frame-Options
which helps to prevent clickjacking.X-Content-Type-Options
to avoid MIME type sniffing.Server
to an empty string. This preventsaiohttp
adding its version + Python version; leaking unneeded information.Type of change
Additional information
Checklist
black --fast homeassistant tests
)If user exposed functionality or configuration variables are added/changed:
If the code communicates with devices, web services, or third-party tools:
Updated and included derived files by running:
python3 -m script.hassfest
.requirements_all.txt
.Updated by running
python3 -m script.gen_requirements_all
..coveragerc
.To help with the load of incoming pull requests: