Merge SEC-10: add Permissions-Policy header

This commit is contained in:
2026-03-13 00:49:34 -07:00
2 changed files with 5 additions and 0 deletions

View File

@@ -79,6 +79,7 @@ func assertSecurityHeaders(t *testing.T, h http.Header, label string) {
{"X-Frame-Options", "DENY"},
{"Strict-Transport-Security", "max-age="},
{"Referrer-Policy", "no-referrer"},
{"Permissions-Policy", "camera=()"},
}
for _, c := range checks {
val := h.Get(c.header)