SkillByAIOpen interactive version →

Lesson 15 / 25

Security Headers and Error Handling

Browser defences and safe failures.

Tell the browser how to protect users

HTTP response headers enable browser defences: Content-Security-Policy (script and resource sources), Strict-Transport-Security, X-Content-Type-Options: nosniff, frame-ancestors in CSP (or X-Frame-Options) against clickjacking, Referrer-Policy and Permissions-Policy. Handle errors safely: show users a generic message with a reference ID, log details server-side, fail closed (deny access when an authorisation check errors), and make sure exceptions cannot leave transactions or security state half-updated.

A baseline set of headers

Adjust the CSP to your application.

Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()

Roll out CSP in report-only mode first

Content-Security-Policy-Report-Only shows what would break before you enforce it.

Quick check: What should happen when an authorisation check throws an unexpected error?

  • Deny access (fail closed) and log the error
  • Allow access to avoid annoying users
  • Show the stack trace to the user
  • Retry until it succeeds
Answer

Deny access (fail closed) and log the error — Errors must not grant access.