AWS ivs: Document HTTP security response headers for CreateIngestConfiguration
Summary
Adds documentation of HTTP response headers returned by the API, including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and CORS headers, with links to MDN. Also removes exceptionMessage fields and updates Boto3 SDK label.
Security assessment
The diff documents security-relevant HTTP response headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options) that mitigate XSS, clickjacking, and protocol downgrade attacks. This is security best-practice documentation, not a fix for a specific vulnerability.
Evidence
+ Content-Security-Policy: contentSecurityPolicy
Diff
diff --git a/ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md b/ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md index a216d850f..cf38ead6c 100644 --- a//ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md +++ b//ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md @@ -135,0 +136,7 @@ Required: No + Access-Control-Allow-Origin: accessControlAllowOrigin + Access-Control-Expose-Headers: accessControlExposeHeaders + Cache-Control: cacheControl + Content-Security-Policy: contentSecurityPolicy + Strict-Transport-Security: strictTransportSecurity + X-Content-Type-Options: xContentTypeOptions + X-Frame-Options: xFrameOptions @@ -167,0 +175,37 @@ If the action is successful, the service sends back an HTTP 200 response. +The response returns the following HTTP headers. + +**accessControlAllowOrigin ** + + +See [Access-Control-Allow-Origin](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Allow-Origin) in the MDN Web Docs. + +**accessControlExposeHeaders ** + + +See [Access-Control-Expose-Headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Expose-Headers) in the MDN Web Docs. + +**cacheControl ** + + +See [Cache-Control](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control) in the MDN Web Docs. + +**contentSecurityPolicy ** + + +See [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy) in the MDN Web Docs. + +**strictTransportSecurity ** + + +See [Strict-Transport-Security](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security) in the MDN Web Docs. + +**xContentTypeOptions ** + + +See [X-Content-Type-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Content-Type-Options) in the MDN Web Docs. + +**xFrameOptions ** + + +See [X-Frame-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options) in the MDN Web Docs. + @@ -184,3 +227,0 @@ For information about the errors that are common to all actions, see [Common Err -**exceptionMessage** - - @@ -194,3 +234,0 @@ HTTP Status Code: 403 -**exceptionMessage** - - @@ -204,3 +241,0 @@ HTTP Status Code: 403 -**exceptionMessage** - - @@ -214,3 +248,0 @@ HTTP Status Code: 402 -**exceptionMessage** - - @@ -241 +273 @@ For more information about using this API in one of the language-specific AWS SD - * [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/CreateIngestConfiguration) + * [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/CreateIngestConfiguration)