INNER CODE UNIT · Python
send_with_headers
caura-ai/caura · core-api/src/core_api/app.py:121
async def send_with_headers(message):
if message["type"] == "http.response.start":
existing = [(k, v) for k, v in message.get("headers", []) if k not in _SECURITY_HEADER_KEYS]
message = {**message, "headers": [*existing, *_SECURITY_HEADERS_ENCODED]}
await send(message)
await self.app(scope, receive, send_with_headers)
# Secrets that ship with a known placeholder and MUST be replaced in production.
# Module scope rather than a local, so the property is testable: a test
# parametrized over this mapping covers whatever is added next, instead of
# re-asserting presence for jwt_secret alone and leaving the following entry to
# be found the way this one was.
_DANGEROUS_DEFAULTS = {
"jwt_secret": "change-me-in-production",
}