AWS ivs: Document HTTP security response headers for UpdateIngestConfiguration
Summary
Added documentation of HTTP response headers returned by the API, including Access-Control-Allow-Origin, Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, and X-Frame-Options, with MDN references.
Security assessment
The change documents security-relevant HTTP response headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) that mitigate XSS, clickjacking, and transport downgrade; it is security documentation rather than a fix for a specific vulnerability.
Evidence
+ Content-Security-Policy: contentSecurityPolicy
Diff
diff --git a/ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md b/ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md index e8e8c7536..d982790a5 100644 --- a//ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md +++ b//ivs/latest/RealTimeAPIReference/API_UpdateIngestConfiguration.md @@ -71,0 +72,7 @@ Required: No + Access-Control-Allow-Origin: accessControlAllowOrigin + Access-Control-Expose-Headers: accessControlExposeHeaders + Cache-Control: cacheControl + Content-Security-Policy: contentSecurityPolicy + Strict-Transport-Security: strictTransportSecurity + X-Content-Type-Options: xContentTypeOptions + X-Frame-Options: xFrameOptions @@ -103,0 +111,37 @@ If the action is successful, the service sends back an HTTP 200 response. +The response returns the following HTTP headers. + +**accessControlAllowOrigin ** + + +See [Access-Control-Allow-Origin](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Allow-Origin) in the MDN Web Docs. + +**accessControlExposeHeaders ** + + +See [Access-Control-Expose-Headers](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Access-Control-Expose-Headers) in the MDN Web Docs. + +**cacheControl ** + + +See [Cache-Control](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control) in the MDN Web Docs. + +**contentSecurityPolicy ** + + +See [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy) in the MDN Web Docs. + +**strictTransportSecurity ** + + +See [Strict-Transport-Security](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security) in the MDN Web Docs. + +**xContentTypeOptions ** + + +See [X-Content-Type-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Content-Type-Options) in the MDN Web Docs. + +**xFrameOptions ** + + +See [X-Frame-Options](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options) in the MDN Web Docs. + @@ -120,3 +163,0 @@ For information about the errors that are common to all actions, see [Common Err -**exceptionMessage** - - @@ -130,3 +170,0 @@ HTTP Status Code: 403 -**exceptionMessage** - - @@ -140,3 +177,0 @@ HTTP Status Code: 409 -**exceptionMessage** - - @@ -150,3 +184,0 @@ HTTP Status Code: 403 -**exceptionMessage** - - @@ -160,3 +191,0 @@ HTTP Status Code: 404 -**exceptionMessage** - - @@ -187 +216 @@ For more information about using this API in one of the language-specific AWS SD - * [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/UpdateIngestConfiguration) + * [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/ivs-realtime-2020-07-14/UpdateIngestConfiguration)