Skip to content

Support fixed response headers on internal asset-loader path handlers - #39

Closed
brad-discord wants to merge 1 commit into
11.18.1-discord-1from
brad.buchanan/shell-permissions-policy-header
Closed

brad-discord wants to merge 1 commit into
11.18.1-discord-1from
brad.buchanan/shell-permissions-policy-header

Conversation

@brad-discord

@brad-discord brad-discord commented Oct 7, 2026 •

Copy link
Copy Markdown

Adds an optional responseHeaders map to internal asset-loader path handlers. Closed in favor of #40.

InternalStoragePathHandler serves local files with no response headers, so a
locally served document cannot carry a header-based policy such as
Permissions-Policy. Add an optional responseHeaders map to the internal path
handler config; when present, wrap the handler so the headers are merged onto
each response. A header policy on the top-level document applies to its whole
frame tree and cannot be undone by scripts or a child frame's allow attribute.
@brad-discord

brad-discord commented Oct 8, 2026 •

Copy link
Copy Markdown
Author

Closing; we're going a different direction. Superseded by #40.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant