This is the new AWS CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::CloudFront::ResponseHeadersPolicy SecurityHeadersConfig
A configuration for a set of security-related HTTP response headers. CloudFront adds these headers to HTTP responses that it sends for requests that match a cache behavior associated with this response headers policy.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "ContentSecurityPolicy" :ContentSecurityPolicy, "ContentTypeOptions" :ContentTypeOptions, "FrameOptions" :FrameOptions, "ReferrerPolicy" :ReferrerPolicy, "StrictTransportSecurity" :StrictTransportSecurity, "XSSProtection" :XSSProtection}
YAML
ContentSecurityPolicy:ContentSecurityPolicyContentTypeOptions:ContentTypeOptionsFrameOptions:FrameOptionsReferrerPolicy:ReferrerPolicyStrictTransportSecurity:StrictTransportSecurityXSSProtection:XSSProtection
Properties
ContentSecurityPolicy-
The policy directives and their values that CloudFront includes as values for the
Content-Security-PolicyHTTP response header.For more information about the
Content-Security-PolicyHTTP response header, see Content-Security-Policyin the MDN Web Docs. Required: No
Type: ContentSecurityPolicy
Update requires: No interruption
ContentTypeOptions-
Determines whether CloudFront includes the
X-Content-Type-OptionsHTTP response header with its value set tonosniff.For more information about the
X-Content-Type-OptionsHTTP response header, see X-Content-Type-Optionsin the MDN Web Docs. Required: No
Type: ContentTypeOptions
Update requires: No interruption
FrameOptions-
Determines whether CloudFront includes the
X-Frame-OptionsHTTP response header and the header's value.For more information about the
X-Frame-OptionsHTTP response header, see X-Frame-Optionsin the MDN Web Docs. Required: No
Type: FrameOptions
Update requires: No interruption
ReferrerPolicy-
Determines whether CloudFront includes the
Referrer-PolicyHTTP response header and the header's value.For more information about the
Referrer-PolicyHTTP response header, see Referrer-Policyin the MDN Web Docs. Required: No
Type: ReferrerPolicy
Update requires: No interruption
StrictTransportSecurity-
Determines whether CloudFront includes the
Strict-Transport-SecurityHTTP response header and the header's value.For more information about the
Strict-Transport-SecurityHTTP response header, see Security headers in the Amazon CloudFront Developer Guide and Strict-Transport-Securityin the MDN Web Docs. Required: No
Type: StrictTransportSecurity
Update requires: No interruption
XSSProtection-
Determines whether CloudFront includes the
X-XSS-ProtectionHTTP response header and the header's value.For more information about the
X-XSS-ProtectionHTTP response header, see X-XSS-Protectionin the MDN Web Docs. Required: No
Type: XSSProtection
Update requires: No interruption