Skip to content

Fix X-Powered-By header leak on bypassed endpoints#102

Merged
shenald-dev merged 1 commit intomasterfrom
fix-x-powered-by-leak-3282943813695483731
Apr 30, 2026
Merged

Fix X-Powered-By header leak on bypassed endpoints#102
shenald-dev merged 1 commit intomasterfrom
fix-x-powered-by-leak-3282943813695483731

Conversation

@shenald-dev
Copy link
Copy Markdown
Owner

Disables the X-Powered-By header explicitly at the application level in src/index.js using app.disable('x-powered-by'). This addresses an issue where the /health endpoint, which intentionally bypassed helmet() for performance reasons, was leaking the framework identity. This change also eliminates the minor CPU overhead of allocating and setting the header only for it to be stripped later by downstream middlewares. Added a regression test to ensure /health no longer returns the header.


PR created automatically by Jules for task 3282943813695483731 started by @shenald-dev

…passed endpoints

Co-authored-by: shenald-dev <245350826+shenald-dev@users.noreply.github.com>
@google-labs-jules
Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@shenald-dev shenald-dev added bug Something isn't working security labels Apr 30, 2026
@shenald-dev
Copy link
Copy Markdown
Owner Author

PR is clean and addresses the header leak effectively. Consider adding a brief comment in src/index.js explaining why x-powered-by is disabled for future maintainers.

Reviewed — quality: high

@shenald-dev
Copy link
Copy Markdown
Owner Author

Looks good, merging this in. CI is green and everything checks out 👍

Disables X-Powered-By header globally to prevent leakage from bypassed endpoints and adds a regression test.

@shenald-dev shenald-dev merged commit 3680f90 into master Apr 30, 2026
2 checks passed
@google-labs-jules
Copy link
Copy Markdown
Contributor

PR is clean and addresses the header leak effectively. Consider adding a brief comment in src/index.js explaining why x-powered-by is disabled for future maintainers.

Reviewed — quality: high

Thanks for the review. I've added a comment in src/index.js explaining why the header is disabled.

@google-labs-jules
Copy link
Copy Markdown
Contributor

Looks good, merging this in. CI is green and everything checks out 👍

Disables X-Powered-By header globally to prevent leakage from bypassed endpoints and adds a regression test.

Acknowledged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant