<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Security headers are dropped on non-2xx responses for custom apps]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I am running a custom app on Cloudron 10.0.5 and noticed that three security headers are missing from any response that is not a 2xx or 3xx. I believe the reverse proxy strips them and re-adds its own only on successful responses.</p>
<p dir="auto"><strong>What I measured</strong></p>
<p dir="auto">Running the app locally, outside Cloudron, it emits twelve security headers, identical on every response regardless of status code. Here is a successful response and an authentication failure, both from the same app:</p>
<pre><code>GET /api/health  -&gt;  200 OK
GET /api/me      -&gt;  401 Unauthorized

both carry, byte for byte:
  cross-origin-opener-policy: same-origin
  cross-origin-resource-policy: same-origin
  origin-agent-cluster: ?1
  permissions-policy: camera=(), microphone=(), geolocation=()
  referrer-policy: no-referrer
  strict-transport-security: max-age=15552000; includeSubDomains
  x-content-type-options: nosniff
  x-dns-prefetch-control: off
  x-download-options: noopen
  x-frame-options: DENY
  x-permitted-cross-domain-policies: none
  x-xss-protection: 0
</code></pre>
<p dir="auto">Behind Cloudron, the same two endpoints give:</p>
<pre><code>200 OK    -&gt; nine of the twelve, plus
             Strict-Transport-Security: max-age=63072000
             X-Content-Type-Options: nosniff
             Referrer-Policy: no-referrer

401       -&gt; the same nine, and nothing else
</code></pre>
<p dir="auto">The nine that survive are exactly the ones Cloudron does not manage. The three that disappear are exactly the ones it does. On the 200 they come back with Cloudron's own values and in a different header casing, so they are the proxy's, not the app's.</p>
<p dir="auto"><strong>Two consequences</strong></p>
<p dir="auto">Error responses reach the browser without HSTS, nosniff or a referrer policy, and an app cannot fix this on its own: whatever it emits is removed the same way.</p>
<p dir="auto">The HSTS value Cloudron sets is also weaker than the one the app sent. The app sends <code>max-age=15552000; includeSubDomains</code>, and what reaches the client is <code>max-age=63072000</code> with no <code>includeSubDomains</code>, so subdomain coverage is silently lost.</p>
<p dir="auto"><strong>What I think would fix it</strong></p>
<p dir="auto">Adding <code>always</code> to the <code>add_header</code> directives in the app nginx configuration, so the headers are emitted on every response and not only on 2xx and 3xx. Preserving the upstream value when the app already sets one would also avoid the downgrade, though the <code>always</code> part is the one that matters to me.</p>
<p dir="auto">I did not try to work around this by editing the nginx config, since app configs are rewritten on restart and upgrade.</p>
<p dir="auto">Happy to provide more details or test a fix on my side.</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.cloudron.io/topic/15960/security-headers-are-dropped-on-non-2xx-responses-for-custom-apps</link><generator>RSS for Node</generator><lastBuildDate>Sat, 03 Oct 2026 16:10:01 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15960.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 14 Sep 2026 13:40:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Security headers are dropped on non-2xx responses for custom apps on Mon, 14 Sep 2026 14:32:04 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nanogabi" aria-label="Profile: nanogabi">@<bdi>nanogabi</bdi></a> thanks for the report, it is spot on. I have fixed it for the next release - <a href="https://git.cloudron.io/platform/box/-/commit/57ef2c2fd3baf161f45c1402e3526222998e9b6f" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/platform/box/-/commit/57ef2c2fd3baf161f45c1402e3526222998e9b6f</a></p>
]]></description><link>https://forum.cloudron.io/post/129417</link><guid isPermaLink="true">https://forum.cloudron.io/post/129417</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 14 Sep 2026 14:32:04 GMT</pubDate></item></channel></rss>