#!/usr/bin/env python3
"""Check web security headers on authorized applications."""

from __future__ import annotations

import argparse
from urllib.parse import urlparse

import requests

RECOMMENDED = {
    "strict-transport-security": "Enforce HTTPS with an appropriate max-age after validation.",
    "content-security-policy": "Restrict script, object, frame, and connection sources.",
    "x-content-type-options": "Use nosniff to reduce MIME confusion risk.",
    "x-frame-options": "Use DENY/SAMEORIGIN or CSP frame-ancestors.",
    "referrer-policy": "Limit referrer leakage.",
    "permissions-policy": "Disable unused browser capabilities.",
}


def main() -> int:
    parser = argparse.ArgumentParser(description="Audit common web security headers.")
    parser.add_argument("url", help="Authorized application URL")
    args = parser.parse_args()
    parsed = urlparse(args.url)
    if parsed.scheme not in {"https", "http"} or not parsed.netloc:
        raise SystemExit("Provide a valid http(s) URL")
    response = requests.get(args.url, timeout=10, allow_redirects=True)
    headers = {key.lower(): value for key, value in response.headers.items()}
    print(f"URL: {response.url}")
    print(f"Status: {response.status_code}")
    for header, guidance in RECOMMENDED.items():
        value = headers.get(header)
        status = "present" if value else "missing"
        print(f"{status.upper():7} {header}: {value or guidance}")
    return 0


if __name__ == "__main__":
    raise SystemExit(main())
