# "Missing OWASP secure headers" error in zoom client mac

**URL:** <https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119>\
**Category:** Zoom Apps\
**Created:** [May 9, 2023, 7:33pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119 "2023-05-09T19:33:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![hcubriac66](https://avatars.discourse-cdn.com/v4/letter/h/57b2e6/32.png) [@hcubriac66](https://devforum.zoom.us/u/hcubriac66)\
**Post date:** [May 9, 2023, 7:33pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/1 "2023-05-09T19:33:08Z")

</div>

Hello, [@everyone](https://devforum.zoom.us/groups/everyone). I am facing error `Missing OWASP Secure Headers: ["X-Content-Type-Options","Content-Security-Policy","Referrer-Policy"] for URL` in mac zoom client.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/8/f/8f299229cdefb65b42606167aa3000e1839fc053.png)

```auto
<Helmet>
        <meta http-equiv="X-Content-Type-Options" content="nosniff" />
        <meta http-equiv="Content-Security-Policy" content="default-src 'self' https:; script-src 'self' https://example.vercel.app/; style-src 'self'; img-src *; font-src 'self' data:;" />
        <meta name="referrer" content="no-referrer" />
</Helmet>

```

The app was built in React.js and it works properly in windows zoom desktop client.  
What should I do to get the page loading exactly in mac zoom client?  
Kindly help me please  
Thank you

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [May 10, 2023, 4:47pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/2 "2023-05-10T16:47:52Z")

</div>

It looks like you’re using react-helmet to set meta tags in the client side. Instead, these values should be set as headers that should be sent by the server when the page is requested. In other words, by the time the client receives this page with the meta tags set, it is too late to change the headers.

react-helmet is designed to set data in the HEAD tag of a react app. To set the headers you should use a method on the server side. If you are using Express to serve this application, you can use a similarly named package called ‘helmet’ to set HTTP headers:

> **[helmet](https://www.npmjs.com/package/helmet)**
>
> help secure Express/Connect apps with various HTTP headers. Latest version: 7.0.0, last published: 4 days ago. Start using helmet in your project by running \`npm i helmet\`. There are 3664 other projects in the npm registry using helmet.

Let me know if that helps.

---

<div class="post-metadata">

**Author:** ![hcubriac66](https://avatars.discourse-cdn.com/v4/letter/h/57b2e6/32.png) [@hcubriac66](https://devforum.zoom.us/u/hcubriac66)\
**Post date:** [May 10, 2023, 6:31pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/3 "2023-05-10T18:31:43Z")

</div>

@MaxM Thank you for your reply.

I used `zoomapps-sample-js` as a backend. I am just calling endpoint from the back-end. So I don’t have any express server for now. To resolve this problem, should I build the express server and run the front-end on it?

Thank you again

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [May 11, 2023, 7:15pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/4 "2023-05-11T19:15:47Z")

</div>

The [Basic Sample App](https://github.com/zoom/zoomapps-sample-js) includes an express server that will set these headers so you can run that to get started. Regardless of the backend that you use, you want these headers to be set.

---

<div class="post-metadata">

**Author:** ![hcubriac66](https://avatars.discourse-cdn.com/v4/letter/h/57b2e6/32.png) [@hcubriac66](https://devforum.zoom.us/u/hcubriac66)\
**Post date:** [May 11, 2023, 8:55pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/5 "2023-05-11T20:55:00Z")

</div>

I just build the express backend and set the Secure header

But I’m still getting this error - `Missing OWASP Secure Headers: ["Strict-Transport-Security","X-Content-Type-Options","Content-Security-Policy","Referrer-Policy"] for URL`

My code is here

```auto
app.use(helmet.contentSecurityPolicy({
    directives: {
        defaultSrc: ["'self'"],
        styleSrc: ["'self'", "'unsafe-inline'"],
        scriptSrc: ["'self'", "'unsafe-inline'", "https://appssdk.zoom.us"],
        connectSrc: ["'self'", `wss://https://example.herokuapp.com/sockjs-node`],
        imgSrc: ["'self'", 'data:', 'https://images.unsplash.com'],
        baseUri: ["'self'"],
        formAction: ["'self'"]
    }
}));
app.use(helmet.frameguard({ action: 'sameorigin' })); 
app.use(helmet.referrerPolicy({ policy: 'same-origin' })); 
app.use(helmet.hsts({ maxAge: 31536000 }));
app.use(helmet.noSniff());

```

I’m not sure the error is really related with the secure headers

---

<div class="post-metadata">

**Author:** ![hcubriac66](https://avatars.discourse-cdn.com/v4/letter/h/57b2e6/32.png) [@hcubriac66](https://devforum.zoom.us/u/hcubriac66)\
**Post date:** [May 11, 2023, 11:32pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/6 "2023-05-11T23:32:35Z")

</div>

I tried to fetch URL in zoom app console - `fetch("https://example.herokuapp.com/");`  
Then I get the below error  
 ![Snag_23962aa3](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/3/1/3179dde61640ca8f5fb199395743bd824ed92225.png)

I set the cors and secure headers in express server. What I wanna say is that all works well in windows zoom client.

---

<div class="post-metadata">

**Author:** ![get1page](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/get1page/32/52596_2.png) [@get1page](https://devforum.zoom.us/u/get1page)\
**Post date:** [October 12, 2023, 5:12am UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/7 "2023-10-12T05:12:53Z")

</div>

Hi @MaxM i’m facing the same issue , i added the headers from the front end and also from the backend .net still i’m getting this error

my app is working fine in the windows and linux , but showing the [Error] Missing OWASP Secure Headers: [“X-Content-Type-Options”,“Content-Security-Policy”,“Referrer-Policy”] for URL in macos

---

<div class="post-metadata">

**Author:** ![tommmyy890](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommmyy890/32/50306_2.png) [@tommmyy890](https://devforum.zoom.us/u/tommmyy890)\
**Post date:** [February 20, 2024, 4:51pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/9 "2024-02-20T16:51:24Z")

</div>

Hey Guys, iam Getting the same issue on my side has any buddy figure it out yet ?

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [March 20, 2024, 9:40pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/10 "2024-03-20T21:40:44Z")

</div>

For those of you encountering issues, first check the network tab of the developer console when testing your web page and ensure that you can see the headers are being sent.

If there is an instance where you are sending all headers and still seeing this issue please send a screenshot of what you are seeing in the headers section of the network tab.

---

<div class="post-metadata">

**Author:** ![Mikron](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/mikron/32/18634_2.png) [@Mikron](https://devforum.zoom.us/u/Mikron)\
**Post date:** [October 18, 2024, 10:49am UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/11 "2024-10-18T10:49:29Z")

</div>

What was the solution here. Same problem

---

<div class="post-metadata">

**Author:** ![donte.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/donte.zoom/32/24412_2.png) [@donte.zoom](https://devforum.zoom.us/u/donte.zoom)\
**Post date:** [November 13, 2024, 6:01pm UTC](https://devforum.zoom.us/t/missing-owasp-secure-headers-error-in-zoom-client-mac/88119/12 "2024-11-13T18:01:19Z")

</div>

Hey @Mikron,  
@Mikron ,  
This topic was covered in a recent Zoom App workshop. You can watch the recording here:

[![](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/4/a/4a9d55c725ad15a3a553785ef8cf0a3931ac2159.jpeg "Developer Workshop - Building Your First Zoom App: A Step by Step Tutorial") ](https://www.youtube.com/watch?v=rWl5SBV8Qrs)

The solution is to ensure you’re setting the correct headers on your server. For more information, check out our support documentation on this topic:

> **[Zoom Apps Context - Zoom Developers](https://developers.zoom.us/docs/zoom-apps/zoom-app-context/#utilizing-the-decrypted-values)**
>
> The Zoom Developer Platform is an open platform that allows third-party developers to build applications and integrations upon Zoom’s video-first unified communications platform.
