docs: address code review comments
- Fix test count in SECURITY_AUDIT.md (11 tests, not 24) - Add deprecation note for ALLOW-FROM in X-Frame-Options - Update documentation to recommend CSP frame-ancestors instead Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
+1
-1
@@ -727,7 +727,7 @@ All security headers are configurable via environment variables:
|
||||
- `SECURITY_AUDIT.md` - Updated infrastructure security status
|
||||
|
||||
**Tests:**
|
||||
- `tests/test_security_headers.py` - Comprehensive test suite (24 tests)
|
||||
- `tests/test_security_headers.py` - Comprehensive test suite (11 tests)
|
||||
- Unit tests for individual headers
|
||||
- Integration tests for configuration loading
|
||||
- Security tests for header format validation
|
||||
|
||||
@@ -159,7 +159,7 @@ Prevents the page from being loaded in frames/iframes. Protects against clickjac
|
||||
**Valid Values:**
|
||||
- `DENY` - Page cannot be displayed in a frame (most secure)
|
||||
- `SAMEORIGIN` - Page can only be displayed in a frame on the same origin
|
||||
- `ALLOW-FROM uri` - Page can only be displayed in a frame on the specified origin (deprecated in modern browsers)
|
||||
- ~~`ALLOW-FROM uri`~~ - **Deprecated**: Page can only be displayed in a frame on the specified origin. This directive is deprecated in modern browsers; use CSP `frame-ancestors` directive instead.
|
||||
|
||||
#### X-Content-Type-Options
|
||||
|
||||
|
||||
@@ -141,6 +141,7 @@ def test_x_frame_options_valid_value(client):
|
||||
if "X-Frame-Options" in response.headers:
|
||||
x_frame_value = response.headers["X-Frame-Options"]
|
||||
valid_values = ["DENY", "SAMEORIGIN"]
|
||||
# Note: ALLOW-FROM is deprecated in modern browsers; use CSP frame-ancestors instead
|
||||
assert x_frame_value in valid_values or x_frame_value.startswith(
|
||||
"ALLOW-FROM"
|
||||
), f"Invalid X-Frame-Options value: {x_frame_value}"
|
||||
|
||||
Reference in New Issue
Block a user