Use when reviewing HTTP response headers for defense-in-depth security hardening on any web application.
复制下面这句话,粘贴给 Claude Code、Codex、Cursor 等 AI 编程工具,它会读取安装说明并在你确认后完成安装。
请阅读 https://ai.atlankj.com/install/asset/gh-permissions-policy-8adcc4f6a45d ,按照其中的说明把「permissions-policy」安装到你(当前 AI 工具)中。执行前先告诉我将运行的命令和写入的位置,等我确认。
查看 AI 将读取的安装说明正在读取 GitHub 原文…
内容来自 GitHub 原始文件,由原作者维护。在 GitHub 查看
A site compromised by XSS that has unrestricted camera and microphone access can silently record the user. Permissions-Policy limits which browser APIs are available, reducing attacker capabilities even after a successful injection.
Permissions-Policy to disable browser features your site does not use (camera, microphone, geolocation, payment)Permissions-Policy: camera=(), microphone=(), geolocation=() — empty () means denied to allFeature-Policy — the old syntax is deprecated and only supported in older browsersCheck whether the server sends a Permissions-Policy header and review which browser features are allowed or denied. Identify any powerful features (camera, microphone, geolocation, payment, USB) that are enabled but not required by the application.
Add a Permissions-Policy header that disables all browser features your site does not use. Start with camera=(), microphone=(), geolocation=() and expand the list based on what the application actually needs.
Explain what the Permissions-Policy header does, how it restricts browser APIs like camera and geolocation, and why disabling unused features improves security.
Review server config, headers, forms, and integration points related to Set a Permissions-Policy header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/permissions-policy