Check · Browser protection · default severity low
Permissions-Policy
What Kavach checks
Declares which browser features (camera, mic, geolocation) your site may use.
Why it matters
Limits what injected or embedded code can switch on without the user realising.
How an attacker uses it
- Injected or embedded code asks for the camera or location.
- With no policy, the browser lets it try.
How to fix it
Add: Permissions-Policy: geolocation=(), microphone=(), camera=()
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.