modified: backend/src/server.ts
This commit is contained in:
@@ -26,23 +26,13 @@ const app: Express = express();
|
|||||||
// Trust proxy if behind reverse proxy (nginx, apache, etc)
|
// Trust proxy if behind reverse proxy (nginx, apache, etc)
|
||||||
app.set('trust proxy', true);
|
app.set('trust proxy', true);
|
||||||
|
|
||||||
// Middleware
|
// Middleware - Helmet disabled for HTTP internal use
|
||||||
app.use(helmet({
|
// app.use(helmet({
|
||||||
contentSecurityPolicy: config.nodeEnv === 'production' ? {
|
// contentSecurityPolicy: false,
|
||||||
directives: {
|
// crossOriginOpenerPolicy: false,
|
||||||
defaultSrc: ["'self'"],
|
// crossOriginResourcePolicy: false,
|
||||||
scriptSrc: ["'self'", "'unsafe-inline'", "'unsafe-eval'", "blob:"],
|
// crossOriginEmbedderPolicy: false,
|
||||||
workerSrc: ["'self'", "blob:"],
|
// }));
|
||||||
styleSrc: ["'self'", "'unsafe-inline'"],
|
|
||||||
imgSrc: ["'self'", "data:", "blob:"],
|
|
||||||
fontSrc: ["'self'", "data:"],
|
|
||||||
connectSrc: ["'self'"],
|
|
||||||
},
|
|
||||||
} : false,
|
|
||||||
crossOriginOpenerPolicy: false,
|
|
||||||
crossOriginResourcePolicy: false,
|
|
||||||
crossOriginEmbedderPolicy: false,
|
|
||||||
}));
|
|
||||||
app.use(cors());
|
app.use(cors());
|
||||||
app.use(express.json());
|
app.use(express.json());
|
||||||
app.use(express.urlencoded({ extended: true }));
|
app.use(express.urlencoded({ extended: true }));
|
||||||
|
|||||||
Reference in New Issue
Block a user