पाठ 15 / 25
Security Headers and Error Handling
Browser defences and safe failures.
Tell the browser how to protect users
HTTP response headers enable browser defences: Content-Security-Policy (script and resource sources), Strict-Transport-Security, X-Content-Type-Options: nosniff, frame-ancestors in CSP (or X-Frame-Options) against clickjacking, Referrer-Policy and Permissions-Policy. Handle errors safely: show users a generic message with a reference ID, log details server-side, fail closed (deny access when an authorisation check errors), and make sure exceptions cannot leave transactions or security state half-updated.
A baseline set of headers
Adjust the CSP to your application.
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self'
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()Roll out CSP in report-only mode first
Content-Security-Policy-Report-Only shows what would break before you enforce it.
त्वरित जाँच: What should happen when an authorisation check throws an unexpected error?
- Deny access (fail closed) and log the error
- Allow access to avoid annoying users
- Show the stack trace to the user
- Retry until it succeeds
Answer
Deny access (fail closed) and log the error — Errors must not grant access.