Skip to content
This repository was archived by the owner on Oct 5, 2020. It is now read-only.

Commit 28405ff

Browse files
authored
Merge pull request #301 from grtjn/287-helmet
Fixed #287: added helmet package for slightly better security
2 parents e019112 + 85ae9aa commit 28405ff

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed

app/templates/node-server/node-app.js

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
'use strict';
33

44
var express = require('express');
5+
var helmet = require('helmet');
56
var expressSession = require('express-session');
67
var app = express();
78
var logger = require('morgan');
@@ -11,6 +12,21 @@ var options = require('./utils/options')();
1112
var port = options.appPort;
1213
var environment = options.env;
1314

15+
// Making this middle-tier slightly more secure: https://www.npmjs.com/package/helmet#how-it-works
16+
app.use(helmet({
17+
csp: { // enable and configure
18+
directives: {
19+
defaultSrc: ['"self"']
20+
},
21+
setAllHeaders: true
22+
},
23+
dnsPrefetchControl: true, // just enable, with whatever defaults
24+
xssFilter: { // enabled by default, but override defaults
25+
setOnOldIE: true
26+
},
27+
noCache: false // make sure it is disabled
28+
}));
29+
1430
app.use(expressSession({
1531
name: '@sample-app-name',
1632
secret: '1234567890QWERTY',

app/templates/package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
"body-parser": "^1.14.0",
66
"express": "^4.4.1",
77
"express-session": "^1.5.0",
8+
"helmet": "^2.0.0",
89
"morgan": "^1.6.0"
910
},
1011
"devDependencies": {

0 commit comments

Comments
 (0)