AWS Security ChangesHomeSearch

AWS ivs: Document HTTP security response headers for CreateIngestConfiguration

Service: ivs · 2026-09-27 · Documentation medium

File: ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md

Summary

Adds documentation of HTTP response headers returned by the API, including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and CORS headers, with links to MDN. Also removes exceptionMessage fields and updates Boto3 SDK label.

Security assessment

The diff documents security-relevant HTTP response headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options) that mitigate XSS, clickjacking, and protocol downgrade attacks. This is security best-practice documentation, not a fix for a specific vulnerability.

Evidence

+    Content-Security-Policy: contentSecurityPolicy

Diff

diff --git a/ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md b/ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md
index a216d850f..cf38ead6c 100644
--- a//ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md
+++ b//ivs/latest/RealTimeAPIReference/API_CreateIngestConfiguration.md
@@ -135,0 +136,7 @@ Required: No
+    Access-Control-Allow-Origin: accessControlAllowOrigin
+    Access-Control-Expose-Headers: accessControlExposeHeaders
+    Cache-Control: cacheControl
+    Content-Security-Policy: contentSecurityPolicy
+    Strict-Transport-Security: strictTransportSecurity
+    X-Content-Type-Options: xContentTypeOptions
+    X-Frame-Options: xFrameOptions
@@ -167,0 +175,37 @@ If the action is successful, the service sends back an HTTP 200 response.
+The response returns the following HTTP headers.
+
+**accessControlAllowOrigin **
+    
+
+See [Access-Control-Allow-Origin](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Allow-Origin) in the MDN Web Docs.
+
+**accessControlExposeHeaders **
+    
+
+See [Access-Control-Expose-Headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Expose-Headers) in the MDN Web Docs.
+
+**cacheControl **
+    
+
+See [Cache-Control](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control) in the MDN Web Docs.
+
+**contentSecurityPolicy **
+    
+
+See [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy) in the MDN Web Docs.
+
+**strictTransportSecurity **
+    
+
+See [Strict-Transport-Security](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security) in the MDN Web Docs.
+
+**xContentTypeOptions **
+    
+
+See [X-Content-Type-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Content-Type-Options) in the MDN Web Docs.
+
+**xFrameOptions **
+    
+
+See [X-Frame-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options) in the MDN Web Docs.
+
@@ -184,3 +227,0 @@ For information about the errors that are common to all actions, see [Common Err
-**exceptionMessage**
-    
-
@@ -194,3 +234,0 @@ HTTP Status Code: 403
-**exceptionMessage**
-    
-
@@ -204,3 +241,0 @@ HTTP Status Code: 403
-**exceptionMessage**
-    
-
@@ -214,3 +248,0 @@ HTTP Status Code: 402
-**exceptionMessage**
-    
-
@@ -241 +273 @@ For more information about using this API in one of the language-specific AWS SD
-  * [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/CreateIngestConfiguration)
+  * [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/CreateIngestConfiguration)