Skip to content

Commit ab7cc3c

Browse files
committed
Set stricter CSP header in redirect response
1 parent 8abdc49 commit ab7cc3c

File tree

3 files changed

+3
-2
lines changed

3 files changed

+3
-2
lines changed

HISTORY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
unreleased
22
==========
33

4+
* Set stricter CSP header in redirect response
45
56
- deps: range-parser@~1.2.1
67

index.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -202,7 +202,7 @@ function createRedirectDirectoryListener () {
202202
res.statusCode = 301
203203
res.setHeader('Content-Type', 'text/html; charset=UTF-8')
204204
res.setHeader('Content-Length', Buffer.byteLength(doc))
205-
res.setHeader('Content-Security-Policy', "default-src 'self'")
205+
res.setHeader('Content-Security-Policy', "default-src 'none'")
206206
res.setHeader('X-Content-Type-Options', 'nosniff')
207207
res.setHeader('Location', loc)
208208
res.end(doc)

test/test.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -511,7 +511,7 @@ describe('serveStatic()', function () {
511511
it('should respond with default Content-Security-Policy', function (done) {
512512
request(server)
513513
.get('/users')
514-
.expect('Content-Security-Policy', "default-src 'self'")
514+
.expect('Content-Security-Policy', "default-src 'none'")
515515
.expect(301, done)
516516
})
517517

0 commit comments

Comments
 (0)