"false" is also valid

This commit is contained in:
Daniel Rentz
2018-09-24 14:55:59 +02:00
parent 98fb32f24b
commit 120fd43ea0
2 changed files with 12 additions and 4 deletions
+8
View File
@@ -76,6 +76,14 @@ function contentSecurityPolicyTest() {
loose: false,
setAllHeaders: true
}));
app.use(helmet.contentSecurityPolicy({
directives: {
reportUri: false,
'report-uri': false,
reportTo: false,
'report-to': false
}
}));
}
/**
+4 -4
View File
@@ -69,8 +69,8 @@ declare namespace helmet {
objectSrc?: HelmetCspDirectiveValue[];
pluginTypes?: HelmetCspDirectiveValue[];
prefetchSrc?: HelmetCspDirectiveValue[];
reportTo?: HelmetCspDirectiveValue;
reportUri?: HelmetCspDirectiveValue;
reportTo?: HelmetCspDirectiveValue | false;
reportUri?: HelmetCspDirectiveValue | false;
requireSriFor?: HelmetCspRequireSriForValue[];
sandbox?: HelmetCspSandboxDirective[];
scriptSrc?: HelmetCspDirectiveValue[];
@@ -95,8 +95,8 @@ declare namespace helmet {
'object-src'?: HelmetCspDirectiveValue[];
'plugin-types'?: HelmetCspDirectiveValue[];
'prefetch-src'?: HelmetCspDirectiveValue[];
'report-to'?: HelmetCspDirectiveValue;
'report-uri'?: HelmetCspDirectiveValue;
'report-to'?: HelmetCspDirectiveValue | false;
'report-uri'?: HelmetCspDirectiveValue | false;
'require-sri-for'?: HelmetCspRequireSriForValue[];
'sandbox'?: HelmetCspSandboxDirective[];
'script-src'?: HelmetCspDirectiveValue;