Configure Security Response Headers
Overview
This page describes how to configure HTTP response headers that enhance the security of your Bloomreach Content delivery application.
When to Use
Configure security-related HTTP response headers to help prevent browser-based vulnerabilities. Common headers include HTTP Strict-Transport-Security (HSTS) and Content-Security-Policy. For a full list of recommended headers and best practices, refer to the OWASP Secure Headers Project.
You can apply these headers at the virtual host, mount, or sitemap item level.
Prerequisites
- Access to the Console to modify JCR nodes.
- Familiarity with your project's host, mount, or sitemap item configuration structure.
Implementation
You can add or override HTTP response headers by setting the multi-valued String property hst:responseheaders on the relevant node.
Configure Headers on a Virtual Host
Set the hst:responseheaders property on a virtual host node to apply headers to all sites under that host.
/hst:hst/hst:hosts/production/com/myproject/www: jcr:primaryType: hst:virtualhost hst:responseheaders: ['Content-Security-Policy: script-src ''self''', 'Strict-Transport-Security: max-age=31536000 ; includeSubDomains'] /hst:root: jcr:primaryType: hst:mount hst:homepage: root hst:mountpoint: /hst:hst/hst:sites/myproject
This example sets the following headers for the virtual host www.myproject.com and all mounted sites:
Content-Security-Policy: script-src 'self'
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Configure Headers on a Mount
Set the hst:responseheaders property on a mount node to apply headers to a specific site or mount.
/hst:hst/hst:hosts/production/com/myproject/www/hst:root: jcr:primaryType: hst:mount hst:homepage: root hst:mountpoint: /hst:hst/hst:sites/myproject hst:responseheaders: ['Content-Security-Policy: script-src ''self''', 'Strict-Transport-Security: max-age=31536000 ; includeSubDomains']
Configure Headers on a Sitemap Item
Set the hst:responseheaders property on a sitemap item node to apply headers to a specific page or route.
/hst:hst/hst:configurations/myproject/hst:sitemap/news: jcr:primaryType: hst:sitemapitem hst:componentconfigurationid: hst:pages/newslist hst:pagetitle: List of News Items hst:relativecontentpath: news hst:responseheaders: ['Content-Security-Policy: script-src ''self''', 'Strict-Transport-Security: max-age=31536000 ; includeSubDomains']
Verification
After configuring the headers, deploy your changes and verify that the expected HTTP response headers are present in responses from the relevant endpoints. Use browser developer tools or command-line tools such as curl to inspect the headers.