Hello, our compliance department has identified that our store on Shopify is missing two important security headers:
They are requesting that we fix that in a shortest amount of time. However, I haven't found a way to set those anywhere inside Shopify Admin site. Setting those headers inside template does not have any effect as well, because these are server side headers, and need to be set on the server side.
Please advise how can a Shopify store owner configure the required security headers, or when Shopify will start supporting the above mentioned 2 security headers?
Truly hope to hear back from you on this soon.
Find it astonishing that no one got back to you regarding this, and I wonder about the exact same thing. When will we be able to set basic security headers our selves, or why wouldn't their servers support those security headers by default?
I see them missing on a lot of websites (both big world-wide brands and smaller sites too – including basically all Shopify sites).
@cskur Did you ever find a solution for this as I need this exact thing?
Thanks in advance!