apoorv-2204

apoorv-2204

How do I set security header for phoenix elixir application.

I used this plug, but its not working.

defmodule Provider.Plugs.SecurityHeaders do
  @moduledoc """
  put response header for security
  """
  import Plug.Conn

  def init(opts), do: opts

  def call(conn, _opts) do
    conn
    |> put_resp_header("x-frame-options", "DENY")
    |> put_resp_header("content-security-policy", "frame-src 'self'; frame-ancestors 'none'")
    |> put_resp_header("x-content-type-options", "nosniff")
    |> put_resp_header("referrer-policy", "no-referrer")
    |> put_resp_header("cross-origin-opener-policy", "same-origin")
    |> put_resp_header("cross-origin-embedder-policy", "unsafe-none")
    |> put_resp_header("cross-origin-resource-policy", "same-origin")
    |> put_resp_header("strict-transport-security", "max-age=31536000; includeSubDomains")
  end
end

pipeline :browser do
    plug(:accepts, ["html"])
    plug(:fetch_session)
    # plug :fetch_flash
    plug(:fetch_live_flash)
    plug(:put_root_layout, {Provider.LayoutView, :root})
    plug(:protect_from_forgery)
    plug(:put_secure_browser_headers)
    plug(:load_information)
    plug(:fetch_current_user)
    plug(Provider.Plugs.CSP)
    plug(Provider.Plugs.SecurityHeaders)
  end

Showing Posts 1 to 7

benwilson512

benwilson512

Author of Craft GraphQL APIs in Elixir with Absinthe

Can you elaborate on what this means? What did you expect to have happen, and what did happen?

apoorv-2204

apoorv-2204 OP

Security headers are not being sent with the response.

It means security headers are not being set

apoorv-2204

apoorv-2204 OP

I just want to set HTTP security headers for the phoenix application how do i do that?

hubertlepicki

hubertlepicki

You, sir or madam, need to work on your communication skills. You will not receive help if you’re unable to express yourself and describe the problem.

absowoot

absowoot

Have a look at the documentation for put_secure_browser_headers.

A custom headers map may also be given to be merged with defaults. It is recommended for custom header keys to be in lowercase, to avoid sending duplicate keys in a request. Additionally, responses with mixed-case headers served over HTTP/2 are not considered valid by common clients, resulting in dropped responses.

pipeline :browser do
    ...
    plug :put_secure_browser_headers,
    %{
         "content-security-policy" =>
         "frame-src 'self'; frame-ancestors 'none'"
     }
end
apoorv-2204

apoorv-2204 OP

But I have a seperate plug for putting csp.

But I want to put http security headers

X-Content-Type-Options: nosniff
Cross-Origin-Embedder-Policy
Cross-Origin-Opener-Policy:

etc.
I am currently using a plug,which puts response headers on incoming request from browser,
Is this the correct way to do it?
what is the correct way to set the security headers apart from CSP.

apoorv-2204

apoorv-2204 OP

okay I wil improve

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
peck
Hi everyone. My team and I have been working on a fairly modest app based around video streaming and chat, but we’ve landed a customer t...
New
bradley
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
unaware8150
Hello folks! So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
Alvinkariuki
How Can I Optimise Compile Time Dependencies I have been building an elixir application for about 2 years now. Many modules and files ha...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mudasobwa
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
juhalehtonen
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews