Skip to content

Commit

Permalink
Updated to send hsts in https header
Browse files Browse the repository at this point in the history
  • Loading branch information
jackycute committed Mar 15, 2016
1 parent f889ffa commit d69d65e
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 0 deletions.
8 changes: 8 additions & 0 deletions app.js
Expand Up @@ -17,6 +17,7 @@ var imgur = require('imgur');
var formidable = require('formidable');
var morgan = require('morgan');
var passportSocketIo = require("passport.socketio");
var helmet = require('helmet');

//core
var config = require("./config.js");
Expand Down Expand Up @@ -92,6 +93,13 @@ var sessionStore = new MongoStore({
//compression
app.use(compression());

// use hsts to tell https users stick to this
app.use(helmet.hsts({
maxAge: 31536000 * 1000, // 365 days
includeSubdomains: true,
preload: true
}));

//session
app.use(session({
name: config.sessionname,
Expand Down
1 change: 1 addition & 0 deletions package.json
Expand Up @@ -22,6 +22,7 @@
"express-session": "^1.13.0",
"formidable": "^1.0.17",
"highlight.js": "^9.1.0",
"helmet": "^1.3.0",
"imgur": "^0.1.7",
"jsdom-nogyp": "^0.8.3",
"kerberos": "0.0.17",
Expand Down

0 comments on commit d69d65e

Please sign in to comment.