Skip to content

Commit

Permalink
Set stricter CSP header in redirect & error responses
Browse files Browse the repository at this point in the history
  • Loading branch information
dougwilson committed May 10, 2019
1 parent 836ed62 commit 7e4e845
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 4 deletions.
5 changes: 5 additions & 0 deletions HISTORY.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
unreleased
==========

* Set stricter CSP header in redirect & error responses

0.17.0 / 2019-05-03
===================

Expand Down
4 changes: 2 additions & 2 deletions index.js
Original file line number Diff line number Diff line change
Expand Up @@ -288,7 +288,7 @@ SendStream.prototype.error = function error (status, err) {
res.statusCode = status
res.setHeader('Content-Type', 'text/html; charset=UTF-8')
res.setHeader('Content-Length', Buffer.byteLength(doc))
res.setHeader('Content-Security-Policy', "default-src 'self'")
res.setHeader('Content-Security-Policy', "default-src 'none'")
res.setHeader('X-Content-Type-Options', 'nosniff')
res.end(doc)
}
Expand Down Expand Up @@ -493,7 +493,7 @@ SendStream.prototype.redirect = function redirect (path) {
res.statusCode = 301
res.setHeader('Content-Type', 'text/html; charset=UTF-8')
res.setHeader('Content-Length', Buffer.byteLength(doc))
res.setHeader('Content-Security-Policy', "default-src 'self'")
res.setHeader('Content-Security-Policy', "default-src 'none'")
res.setHeader('X-Content-Type-Options', 'nosniff')
res.setHeader('Location', loc)
res.end(doc)
Expand Down
4 changes: 2 additions & 2 deletions test/send.js
Original file line number Diff line number Diff line change
Expand Up @@ -365,7 +365,7 @@ describe('send(file).pipe(res)', function () {
request(createServer({ root: fixtures }))
.get('/pets')
.expect('Location', '/pets/')
.expect('Content-Security-Policy', "default-src 'self'")
.expect('Content-Security-Policy', "default-src 'none'")
.expect(301, done)
})

Expand Down Expand Up @@ -400,7 +400,7 @@ describe('send(file).pipe(res)', function () {
it('should respond with default Content-Security-Policy', function (done) {
request(createServer({ root: fixtures }))
.get('/foobar')
.expect('Content-Security-Policy', "default-src 'self'")
.expect('Content-Security-Policy', "default-src 'none'")
.expect(404, done)
})

Expand Down

0 comments on commit 7e4e845

Please sign in to comment.