Skip to content

Include security headers - #4517

Merged
jdeanquin-dg merged 2 commits into
developfrom
fix/AMP-31205/PIDC-Security-Test-Report-fix
Oct 7, 2026
Merged

jdeanquin-dg merged 2 commits into
developfrom
fix/AMP-31205/PIDC-Security-Test-Report-fix

Conversation

@brianbrix

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI lite review requested due to automatic review settings October 6, 2026 14:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical CSP trust and documentation issues remain unresolved.

Review effort: Lite
Findings: 2 High severity

Open (2)
What changed in this PR

Adds global security headers and expands the CSP for external resources.

Changes:

  • Registers SecurityHeadersFilter globally.
  • Adds CSP directives for frames, workers, and external resources.
  • Documents the updated security policy.

Two critical issues remain: script-src https: trusts all HTTPS origins, and CSP documentation is inconsistent with the configured directives.

File Summary
amp/​src/​main/​webapp/​WEB-INF/​web.xml Registers the security headers filter globally.
amp/​src/​main/​java/​org/​digijava/​kernel/​web/​SecurityHeadersFilter.java Defines security headers and CSP policy; requires a specific script-origin allowlist and synchronized documentation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread amp/src/main/java/org/digijava/kernel/web/SecurityHeadersFilter.java Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 6, 2026 14:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the critical CSP exposure and unpinned CDN script, and add form-action protection.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (2)

@jdeanquin-dg
jdeanquin-dg merged commit e067f91 into develop Oct 7, 2026
4 of 6 checks passed
@jdeanquin-dg
jdeanquin-dg deleted the fix/AMP-31205/PIDC-Security-Test-Report-fix branch October 7, 2026 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants