Fix security headers are not configured in Koa
The application does not set the baseline security response headers. Without them a browser will not enforce HTTPS, will guess content types, and will allow the page to be framed. Headers set by a CDN or ingress are invisible to static analysis, so this rule reports lower confidence when it finds no header configuration at all.
medium likely Koa CWE-693 / OWASP A05:2021
The vulnerable pattern in Koa
This finding comes from the Koa fixture in the owlwarden test suite. Without these headers the browser enforces nothing: strict-transport-security forces HTTPS for future requests; content-security-policy limits which scripts and origins the page may load; x-content-type-options stops browsers guessing a response's content type; x-frame-options blocks clickjacking via framing; referrer-policy stops URLs leaking to third parties.
The corrected handler
Register koa-helmet before your routes; it sets all of these.
import helmet from 'koa-helmet'
app.use(helmet())
If you are not using Koa
Set these response headers at the edge or in the app: strict-transport-security, content-security-policy, x-content-type-options, x-frame-options, referrer-policy.
Check your own repository
npx owlwarden scan
npx owlwarden explain security-headers-missing
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other Koa checks
Rules with a tested Koa example.
- cors-permissive medium Cross-origin policy accepts any origin
- hardcoded-secret high Credential hardcoded in source
- insecure-cookie medium Cookie set without its protective attributes
- install-lifecycle-script medium Package declares an install-time script
- open-redirect medium Redirect target comes from the caller
- sensitive-data-logged medium Sensitive data written to a log
- sql-injection high SQL query built by string interpolation
- ssrf high Server fetches a URL the caller controls
- stack-trace-leak high Stack trace leaked in error response
- weak-crypto high Broken cryptographic primitive protecting a secret
security-headers-missing for every framework / All rules / owlwarden