Skip to main content

Security Headers

The IDP enables strict security headers via Helmet (apps/idp/src/main.ts).

Headers

HeaderValue
HSTSmax-age=31536000; includeSubDomains; preload
Referrer-Policystrict-origin-when-cross-origin
X-Content-Type-Optionsnosniff
X-Frame-Optionsdeny (via frameguard)
COOP/CORPDefaults

Content Security Policy

default-src 'self';
script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com;
style-src 'self' 'unsafe-inline' https:;
img-src 'self' data: https:;
frame-ancestors 'none';
base-uri 'self';
form-action 'self'

Customization

Tune CSP per tenant if additional third-parties are required. Modify the Helmet configuration in apps/idp/src/main.ts.