Skip to content

Commit 6044a64

Browse files
authored
Merge pull request #61 from codeforjapan/fix/secure-header
セキュリティリスクを低減させるレスポンスヘッダーを入れる
2 parents 35d21e6 + 91076a6 commit 6044a64

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

app/entry.server.tsx

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,5 +15,15 @@ export default async function handleRequest(
1515
routerContext,
1616
loadContext,
1717
);
18+
19+
response.headers.set(
20+
"Strict-Transport-Security",
21+
"max-age=63072000; includeSubDomains; preload",
22+
);
23+
response.headers.set("Referrer-Policy", "strict-origin-when-cross-origin");
24+
response.headers.set("X-Content-Type-Options", "nosniff");
25+
response.headers.set("X-Frame-Options", "DENY");
26+
response.headers.set("X-Permitted-Cross-Domain-Policies", "none");
27+
1828
return response;
1929
}

0 commit comments

Comments
 (0)