AWS Security ChangesHomeSearch

AWS ivs: Document HTTP security response headers for UpdateIngestConfiguration

Service: ivs · 2026-09-27 · Documentation medium

File: ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md

Summary

Added documentation of HTTP response headers returned by the API, including Access-Control-Allow-Origin, Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, and X-Frame-Options, with MDN references.

Security assessment

The change documents security-relevant HTTP response headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) that mitigate XSS, clickjacking, and transport downgrade; it is security documentation rather than a fix for a specific vulnerability.

Evidence

+    Content-Security-Policy: contentSecurityPolicy

Diff

diff --git a/ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md b/ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md
index e8e8c7536..d982790a5 100644
--- a//ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md
+++ b//ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md
@@ -71,0 +72,7 @@ Required: No
+    Access-Control-Allow-Origin: accessControlAllowOrigin
+    Access-Control-Expose-Headers: accessControlExposeHeaders
+    Cache-Control: cacheControl
+    Content-Security-Policy: contentSecurityPolicy
+    Strict-Transport-Security: strictTransportSecurity
+    X-Content-Type-Options: xContentTypeOptions
+    X-Frame-Options: xFrameOptions
@@ -103,0 +111,37 @@ If the action is successful, the service sends back an HTTP 200 response.
+The response returns the following HTTP headers.
+
+**accessControlAllowOrigin **
+    
+
+See [Access-Control-Allow-Origin](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Allow-Origin) in the MDN Web Docs.
+
+**accessControlExposeHeaders **
+    
+
+See [Access-Control-Expose-Headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Expose-Headers) in the MDN Web Docs.
+
+**cacheControl **
+    
+
+See [Cache-Control](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control) in the MDN Web Docs.
+
+**contentSecurityPolicy **
+    
+
+See [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy) in the MDN Web Docs.
+
+**strictTransportSecurity **
+    
+
+See [Strict-Transport-Security](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security) in the MDN Web Docs.
+
+**xContentTypeOptions **
+    
+
+See [X-Content-Type-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Content-Type-Options) in the MDN Web Docs.
+
+**xFrameOptions **
+    
+
+See [X-Frame-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options) in the MDN Web Docs.
+
@@ -120,3 +163,0 @@ For information about the errors that are common to all actions, see [Common Err
-**exceptionMessage**
-    
-
@@ -130,3 +170,0 @@ HTTP Status Code: 403
-**exceptionMessage**
-    
-
@@ -140,3 +177,0 @@ HTTP Status Code: 409
-**exceptionMessage**
-    
-
@@ -150,3 +184,0 @@ HTTP Status Code: 403
-**exceptionMessage**
-    
-
@@ -160,3 +191,0 @@ HTTP Status Code: 404
-**exceptionMessage**
-    
-
@@ -187 +216 @@ For more information about using this API in one of the language-specific AWS SD
-  * [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/UpdateIngestConfiguration)
+  * [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/UpdateIngestConfiguration)