You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Security headers on pass-through responses
Added
Security headers on every pass-through response. The adapter applies the engine's ResponseHeaders() set in one loop before the handler writes, so clean responses carry the same default header set as blocked ones (mirroring the engine's process_response). Disabling SecurityHeaders restores the header-free pass, and config overrides plus custom headers flow through the adapter untouched.