Skip to content

[P2][security] Security headers: nosniff, restrictive CORS, full CSP across companion servers #7

Description

@Toqsick

Source: RepoLens Security-Audit 2026-08-16 (findings security/security-headers/001–006, adversarial-verified ✅)

superpowers-brainstorming companion server.cjs + live-data-server.py:

  • Missing X-Content-Type-Options: nosniff
  • Access-Control-Allow-Origin: * on every /api/* route (live-data-server.py)
  • CSP only restricts frame-ancestors — user-authored HTML can exfiltrate
  • Docs (sse-v2-architecture.md) prescribe * as required pattern

Suggested fix: central header helper (nosniff + restrictive CORS + full CSP), fix the doc pattern, add tests.

Activity

  1. Toqsick commented on Aug 16, 2026

    @Toqsick
    OwnerAuthor

    Triage 2026-08-16: ProjectZomboiD #3–#7 sind heute gefixt und geschlossen (PR #8). my-agent-tools-Härtung ist das nächste RepoLens-Backlog, geplante Reihenfolge: #9 (Path-Traversal) → #8 (Skill-Docs) → #7 (Security-Header) → #6/#5 (Rate-Limiting). Die Visibility-Entscheidung (public vs. private) fällt nach der Härte-Runde.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions