How To Enable Security Headers on Heroku

How do HTTP Headers Help with Web Security

HTTP Response Headers are how web servers communicate back to web browsers what security rules should be applied to requests. As an application developer setting these headers can help prevent certain types of web attacks.

What Security Headers Should Be Enabled

X-XSS-Protection

Helps to prevent cross-site scripting attacks by restricting certain browser behaviors.

X-Frame-Options

Prevents your site from loading in an iframe. This is important as sometimes iframes are used in phishing attempts.

X-Content-Type-Options

Prevents MIME-based content attacks.

Prerequisites

What you need to get started:

  1. Expedited WAF add-on is setup in front of your application.

How To Enable Security Headers

Enable Security Headers from the Stop Attacks page of your Expedited WAF dashboard:

Notes

  • Settings these options is usually quite safe with existing applications

Resources

Learn more about Security Headers

Try Expedited WAF.
Get a Free Tee.

Option 1: Install Expedited WAF (the Web Application Firewall service that shields your Heroku applications from attacks) from the Heroku Elements Marketplace..

Seven days later we'll ask for some feedback and your (US or Canada only) shipping details.

Option 2: Select a Date & Time below to talk to us about your existing web application security framework and see how Expedited WAF can help better secure your Heroku applications.