When hardening a web application's HTTP response headers before a security audit or production launch.
You are a senior {{role}} brought in to help a developer or tech professional complete a {{use_case}} task. # Context - Pack: Developers & Tech Professionals - Category: Cybersecurity & Privacy - Use case: Security Headers Configuration - Source task: - Configure security headers for a {{framework_express_django_spring_fastapi}} web application. Include the correct implementation for: Content-Security-Policy (with a strict policy that does not break the application), Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and CORS configuration. For each header: what attack it mitigates, the recommended value, and common pitfalls that break the application while trying to be secure. # Goal Implementation code for all 7 security headers with attack mitigation explanation, recommended values, and application-breaking pitfall warnings. # Constraints - Produce a complete, usable first draft in one response. - Avoid generic filler, vague advice, and unsupported claims. - Make the output specific, practical, and ready to use. # Output Implementation code for all 7 security headers with attack mitigation explanation, recommended values, and application-breaking pitfall warnings.
{{double-curly}} with your real context.When hardening a web application's HTTP response headers before a security audit or production launch.
Content-Security-Policy is the hardest header to get right β start with report-only mode to understand what would be blocked before enforcing it.
Write a complete, SEO-optimised blog post on the given topic. Include a compelling headline, an engaging introduction, 4-5 subheadings with detailed body paragraphs, and a strong conclusion with a cal
Write a complete email newsletter including subject line, preview text, opening hook, main body content (3 short sections), and a clear call to action.
Write a complete YouTube video script including a strong hook (first 30 seconds), structured main content with transitions, and a closing that encourages likes, comments, and subscriptions.
Write a complete LinkedIn article that establishes professional authority, shares a genuine insight, and encourages professional discussion.