Skip to content

Production HSTS hardening: preload, no-store on error pages, and CSP report-only diagnostic #215

Description

@kilodesodiq-arch

Problem Statement. buildHelmetOptions in app/backend/src/common/security/security.module.ts
sets HSTS preload: true only when NODE_ENV === 'production'. There is no test
asserting the header is present, no automated check for misconfigurations, and no
report-uri for CSP violations — a regression can silently drop security headers without any
alert.

Why it matters. These are baseline, browser-enforced protections. Their absence is
indistinguishable from a healthy deploy without instrumentation.

Technical Context. Helmet is installed and wired; the secure-headers default profile
covers most directives but not report-uri for Content-Security-Policy.

Expected Outcome. A security-headers.e2e-spec.ts runs in CI against a staging boot
and asserts every required header (Strict-Transport-Security, X-Content-Type-Options,
Referrer-Policy, Cross-Origin-Resource-Policy, X-Frame-Options,
Cross-Origin-Opener-Policy) is present in production-mode responses and absent in
development for the dev-only overrides.

Acceptance Criteria.

Implementation Notes. Extend the existing Helmet Options builder rather than
overriding in middleware.

Files or modules likely to be affected. src/common/security/security.module.ts,
app/backend/test/security-headers.e2e-spec.ts (new).

Dependencies. #11 (CSP report endpoint).

Difficulty. Easy
Estimated effort. S



Backlog item #7 from `docs/maintainer-issue-backlog.md.

Activity

  1. bernardev254 commented on Jul 20, 2026

    @bernardev254

    Hello,

    I’d like to propose adding an E2E test (security-headers.e2e-spec.ts) to validate critical security headers (HSTS, CSP with report-uri, etc.) in production mode. Currently, there’s no automated check for misconfigurations, risking silent regressions.

    Goal: Assert headers are present in production and absent in development, using the existing Helmet setup. Depends on #11 for the CSP endpoint.

    Let me know if I can assist!

    Best,
    Bernard

  2. P3az3 commented on Jul 21, 2026

    @P3az3
    Contributor

    I can work on this, please assign me I have experience as a develoiper

  3. grantfox-oss commented on Jul 21, 2026

    @grantfox-oss

    🦊 GrantFox — @P3az3 has been assigned to this issue as part of the Official Campaign | FWC26 campaign!

    Next steps:

    1. Open a Pull Request referencing this issue (e.g., Closes #215)
    2. Your PR will be reviewed by the ChainForgee maintainers

    Good luck! Track your progress on GrantFox.

  4. grantfox-oss commented on Jul 22, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox as part of the Official Campaign | FWC26 campaign!

    @P3az3's PR #399 was approved and merged by @kilodesodiq-arch.

    🏆 @P3az3: You earned 35 FoxPoints for this contribution! Your current tier: Explorer (258 total points). Track your full progress on GrantFox.

    👏 Great work, @P3az3! Keep contributing to ChainForgee.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions