From 9d22c75016323dc566c8af7b49f3fba229930583 Mon Sep 17 00:00:00 2001 From: lilleman Date: Sat, 20 Jun 2026 01:18:24 +0200 Subject: [PATCH] =?UTF-8?q?=C2=A79=20response=20security=20headers=20(todo?= =?UTF-8?q?=20=C2=A79);=20the=20cookies/CSRF/clock-skew=20parts=20of=20thi?= =?UTF-8?q?s=20item=20all=20landed=20in=20=C2=A74=20(HttpOnly/SameSite/Sec?= =?UTF-8?q?ure=20cookies=20in=20cookie.ts,=20the=20signed=20double-submit?= =?UTF-8?q?=20in=20csrf.ts,=20JWT=5FCLOCK=5FSKEW=5FSEC=20leeway=20on=20exp?= =?UTF-8?q?+nbf=20in=20jwt-middleware)=20=E2=80=94=20the=20open=20gap=20wa?= =?UTF-8?q?s=20response=20security=20headers,=20now=20closed.=20New=20pure?= =?UTF-8?q?=20src/security-headers.ts=20(securityHeaders({secure})):=20a?= =?UTF-8?q?=20strict=20CSP=20for=20the=20zero-JS=20core=20=E2=80=94=20scri?= =?UTF-8?q?pt-src=20'self'=20with=20NO=20'unsafe-inline'=20(an=20injected?= =?UTF-8?q?=20