legacy-knowledge-base
公開されました Jun. 30, 2025

HTTP Security Headers Missing on 404 pages

written-by

Apsara Raheja

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text
Note: please note that Liferay has renamed its Liferay Experience Could offerings to Liferay SaaS (formerly LXC) and Liferay PaaS (formerly LXC-SM).

Issue

  • While adding the below security headers in nginx.conf file of the web server:
    add_header Referrer-Policy "no-referrer"; 
    add_header Permissions-Policy "microphone=(),camera=()";
  • The mentioned security headers are reflected for the 200 response pages but not on the 404 not found pages.
  • Steps to check:
    1. Navigate to any page.
    2. Inspect the browser and click on the network tab.
    3. Reload the page and click on the URL of that particular page.
    4. Drop down the response headers.
  • Observed Behavior: Security headers are visible for 200 responses but not on the 404 response.
  • Expected Behavior: Security headers should be visible for every response page.

Environment

  • Liferay Paas
  • Nginx

Resolution

  • To achieve the desired behavior, add the 'always' parameter at the end of the headers, like below:
    add_header Referrer-Policy "no-referrer" always; 
    add_header Permissions-Policy "microphone=(),camera=()" always;

Additional Information

did-this-article-resolve-your-issue

legacy-knowledge-base