Skip to content

fix(secure-headers): output standard empty parentheses () instead of none for disabled Permissions-Policy directives - #5197

Merged
yusukebe merged 1 commit into
honojs:mainfrom
spellsaif:fix/permissions-policy-syntax
Aug 9, 2026
Merged

yusukebe merged 1 commit into
honojs:mainfrom
spellsaif:fix/permissions-policy-syntax

Conversation

@spellsaif

Copy link
Copy Markdown
Contributor

Historically, Hono's secureHeaders middleware serialized disabled or none value Permissions-Policy directives as none (e.g.,
camera=none). However, according to the modern W3C Structured Fields specification for the Permissions-Policy header, the
keyword none is not a valid value. Instead, the correct syntax to disable a feature for all origins is an empty structured list
represented by empty parentheses ().

This PR updates the serialization in getPermissionsPolicyDirectives to correctly output () instead of none when a directive
value is false or ['none'], ensuring strict compliance with the standard and preventing modern browsers from failing to parse
the header.

The author should do the following, if applicable

- [x] Add tests
- [x] Run tests
- [x] `bun run format:fix && bun run lint:fix` to format the code
- [x] Add [TSDoc](https://tsdoc.org/)/[JSDoc](https://jsdoc.app/about-getting-started) to document the code

@codecov

codecov Bot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.68%. Comparing base (cd31bc1) to head (fc6bf5c).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5197      +/-   ##
==========================================
- Coverage   79.69%   79.68%   -0.01%     
==========================================
  Files         155      155              
  Lines       10892    10896       +4     
  Branches     2280     2282       +2     
==========================================
+ Hits         8680     8683       +3     
- Misses       2212     2213       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@yusukebe
yusukebe merged commit 13a9481 into honojs:main Aug 9, 2026
20 checks passed
@spellsaif

Copy link
Copy Markdown
Contributor Author

Thanks for reviewing and merging this, @yusukebe! Glad we could get the Permissions-Policy serialization aligned with the current specification.

BlankParticle pushed a commit to BlankParticle/hono that referenced this pull request Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants