# Security Headers and Error Handling — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/d-headers

> Browser defences and safe failures.

## Tell the browser how to protect users

HTTP response headers enable browser defences: **Content-Security-Policy** (script and resource sources), **Strict-Transport-Security**, **X-Content-Type-Options: nosniff**, **frame-ancestors** in CSP (or X-Frame-Options) against clickjacking, **Referrer-Policy** and **Permissions-Policy**. Handle errors safely: show users a generic message with a reference ID, log details server-side, **fail closed** (deny access when an authorisation check errors), and make sure exceptions cannot leave transactions or security state half-updated.

## A baseline set of headers

Adjust the CSP to your application.

```text
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
```

## Roll out CSP in report-only mode first

Content-Security-Policy-Report-Only shows what would break before you enforce it.

**Quiz:** What should happen when an authorisation check throws an unexpected error?

- [x] Deny access (fail closed) and log the error
- [ ] Allow access to avoid annoying users
- [ ] Show the stack trace to the user
- [ ] Retry until it succeeds

*Answer:* Deny access (fail closed) and log the error. Errors must not grant access.
