PEPPER-978 and PEPPER-979 adding a few headers as per appsec. #2882
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PEPPER-978 and PEPPER-979
The above tickets were flagged by appsec as must-dos. Resolving them just required adding a few headers. They are added to the backends directly instead of by load balancers or app engine configs so that regardless of deployment technology, the headers are there. Once these are on dev, we'll have appsec validate that things are working properly before promoting to other environments. There are no tests included here because appsec gets to determine whether the deployed app is sending the right headers.
Release