ResponseHeadersPolicySecurityHeadersConfig
A configuration for a set of security-related HTTP response headers. CloudFront adds these headers to HTTP responses that it sends for requests that match a cache behavior associated with this response headers policy.
Contents
- ContentSecurityPolicy
-
The policy directives and their values that CloudFront includes as values for the
Content-Security-PolicyHTTP response header.For more information about the
Content-Security-PolicyHTTP response header, see Content-Security-Policyin the MDN Web Docs. Type: ResponseHeadersPolicyContentSecurityPolicy object
Required: No
- ContentTypeOptions
-
Determines whether CloudFront includes the
X-Content-Type-OptionsHTTP response header with its value set tonosniff.For more information about the
X-Content-Type-OptionsHTTP response header, see X-Content-Type-Optionsin the MDN Web Docs. Type: ResponseHeadersPolicyContentTypeOptions object
Required: No
- FrameOptions
-
Determines whether CloudFront includes the
X-Frame-OptionsHTTP response header and the header's value.For more information about the
X-Frame-OptionsHTTP response header, see X-Frame-Optionsin the MDN Web Docs. Type: ResponseHeadersPolicyFrameOptions object
Required: No
- ReferrerPolicy
-
Determines whether CloudFront includes the
Referrer-PolicyHTTP response header and the header's value.For more information about the
Referrer-PolicyHTTP response header, see Referrer-Policyin the MDN Web Docs. Type: ResponseHeadersPolicyReferrerPolicy object
Required: No
- StrictTransportSecurity
-
Determines whether CloudFront includes the
Strict-Transport-SecurityHTTP response header and the header's value.For more information about the
Strict-Transport-SecurityHTTP response header, see Security headers in the Amazon CloudFront Developer Guide and Strict-Transport-Securityin the MDN Web Docs. Type: ResponseHeadersPolicyStrictTransportSecurity object
Required: No
- XSSProtection
-
Determines whether CloudFront includes the
X-XSS-ProtectionHTTP response header and the header's value.For more information about the
X-XSS-ProtectionHTTP response header, see X-XSS-Protectionin the MDN Web Docs. Type: ResponseHeadersPolicyXSSProtection object
Required: No
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: