Our companies single page React application requires custom AWS/Lambda CSP headers based on route, is this possible?

Viewed 120

Our company runs a CRA single page application through an AWS Cloudfront distribution where we're applying CSP headers for added security.

We have two applications that we would like to isolate without going the mono repo/dual build route, let's call them dashboard and admin panel. We need the dashboard to be fully open when someone visits the URL www.example.com/dashboard, with no CSP headers/iFrame rules blocking, and our admin panel needs to be locked down www.example.com/adminPanel.

Is this possible?

Are there any other solutions besides going entirely different repo, or mono repo?

Really appreciate the help with this one!

exports.handler = (event, context, callback) => {
const { request } = event.Records[0].cf;
const { response } = event.Records[0].cf;
const { headers } = response;
const environment = request.origin.s3.customHeaders['x-env-environment'][0].value;

headers['content-security-policy-report-only'] = [
        {
            key: 'Content-Security-Policy-Report-Only',
            value:
                default_src +
                frame_ancestors,
        },
]
...
0 Answers
Related