From 6b1acf059d142b42ffc98df1402696f86711eb23 Mon Sep 17 00:00:00 2001 From: tgpethan Date: Tue, 5 May 2020 17:40:37 +0100 Subject: [PATCH] Add headers to EUS.js --- EUS.js | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/EUS.js b/EUS.js index 228ca95..a5fb09b 100644 --- a/EUS.js +++ b/EUS.js @@ -76,6 +76,15 @@ module.exports = { res - Response from server */ + // Set some headers + res.set("Strict-Transport-Security", "max-age=31536000; includeSubDomains"); + res.set("X-XSS-Protection", "1; mode=block"); + res.set("Feature-Policy", "fullscreen 'none'"); + res.set("Referrer-Policy", "strict-origin-when-cross-origin"); + res.set("Content-Security-Policy", "block-all-mixed-content;frame-ancestors 'self'"); + res.set("X-Frame-Options", "SAMEORIGIN"); + res.set("X-Content-Type-Options", "nosniff"); + // Check if returned value is true. if (!req.url.includes("/api/")) { // Register the time at the start of the request -- 2.47.0