24 lines
704 B
JavaScript
24 lines
704 B
JavaScript
// Response headers applied to every response (static files and API).
|
|
// The frontend ships no inline script/style, so the CSP can stay strict.
|
|
|
|
const CSP = [
|
|
"default-src 'none'",
|
|
"script-src 'self'",
|
|
"style-src 'self'",
|
|
"img-src 'self' data:",
|
|
"font-src 'self'",
|
|
"connect-src 'self'",
|
|
"base-uri 'none'",
|
|
"form-action 'none'",
|
|
"frame-ancestors 'none'",
|
|
].join('; ');
|
|
|
|
export const SECURITY_HEADERS = Object.freeze({
|
|
'Content-Security-Policy': CSP,
|
|
'X-Content-Type-Options': 'nosniff',
|
|
'X-Frame-Options': 'DENY',
|
|
'Referrer-Policy': 'no-referrer',
|
|
'Cross-Origin-Opener-Policy': 'same-origin',
|
|
'Permissions-Policy': 'camera=(), microphone=(), geolocation=(), payment=()',
|
|
});
|