This is the new AWS CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::CloudFront::ResponseHeadersPolicy SecurityHeadersConfig
A configuration for a set of security-related HTTP response headers. CloudFront adds these headers to HTTP responses that it sends for requests that match a cache behavior associated with this response headers policy.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "ContentSecurityPolicy" :ContentSecurityPolicy, "ContentTypeOptions" :ContentTypeOptions, "FrameOptions" :FrameOptions, "ReferrerPolicy" :ReferrerPolicy, "StrictTransportSecurity" :StrictTransportSecurity, "XSSProtection" :XSSProtection}
YAML
ContentSecurityPolicy:ContentSecurityPolicyContentTypeOptions:ContentTypeOptionsFrameOptions:FrameOptionsReferrerPolicy:ReferrerPolicyStrictTransportSecurity:StrictTransportSecurityXSSProtection:XSSProtection
Properties
- ContentSecurityPolicy
- 
                    The policy directives and their values that CloudFront includes as values for the Content-Security-PolicyHTTP response header.For more information about the Content-Security-PolicyHTTP response header, see Content-Security-Policyin the MDN Web Docs. Required: No Type: ContentSecurityPolicy Update requires: No interruption 
- ContentTypeOptions
- 
                    Determines whether CloudFront includes the X-Content-Type-OptionsHTTP response header with its value set tonosniff.For more information about the X-Content-Type-OptionsHTTP response header, see X-Content-Type-Optionsin the MDN Web Docs. Required: No Type: ContentTypeOptions Update requires: No interruption 
- FrameOptions
- 
                    Determines whether CloudFront includes the X-Frame-OptionsHTTP response header and the header's value.For more information about the X-Frame-OptionsHTTP response header, see X-Frame-Optionsin the MDN Web Docs. Required: No Type: FrameOptions Update requires: No interruption 
- ReferrerPolicy
- 
                    Determines whether CloudFront includes the Referrer-PolicyHTTP response header and the header's value.For more information about the Referrer-PolicyHTTP response header, see Referrer-Policyin the MDN Web Docs. Required: No Type: ReferrerPolicy Update requires: No interruption 
- StrictTransportSecurity
- 
                    Determines whether CloudFront includes the Strict-Transport-SecurityHTTP response header and the header's value.For more information about the Strict-Transport-SecurityHTTP response header, see Security headers in the Amazon CloudFront Developer Guide and Strict-Transport-Securityin the MDN Web Docs. Required: No Type: StrictTransportSecurity Update requires: No interruption 
- XSSProtection
- 
                    Determines whether CloudFront includes the X-XSS-ProtectionHTTP response header and the header's value.For more information about the X-XSS-ProtectionHTTP response header, see X-XSS-Protectionin the MDN Web Docs. Required: No Type: XSSProtection Update requires: No interruption