HarperFast / HarperFast/harper
[Epic] HTTP response security hardening (headers/errors)
Open
- Dominant language
- JavaScript
- Stars
- 89
- Forks
- 10
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 200
Description
Tracking epic for HTTP response security-hardening findings: missing hardening headers, Server-Timing leak, verbose error bodies, and SameSite cookie exposure.
---
_Filed by Claude (Opus 4.8), issue-backlog triage & grouping pass._
Contributor guide
Research direction
This is an umbrella epic covering four HTTP response findings: missing hardening headers, a Server-Timing leak, verbose error bodies, and SameSite cookie exposure. Start by splitting the findings into separate investigations and locating the relevant response-handling entry points; the payload names no files or tests, so completion criteria must be defined for each finding.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- backend-api-design, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100