Merge pull request #29148 from danielrentz/helmet-reporturi-type

helmet: proposed fix for missing callback type for reportUri/reportTo
This commit is contained in:
Andrew Casey
2018-09-24 13:33:50 -07:00
committed by GitHub
2 changed files with 14 additions and 6 deletions
+9 -1
View File
@@ -58,13 +58,21 @@ function contentSecurityPolicyTest() {
disableAndroid: false
};
function reportUriCb(req: express.Request, res: express.Response) { return '/some-uri'; }
function reportOnlyCb(req: express.Request, res: express.Response) { return false; }
app.use(helmet.contentSecurityPolicy());
app.use(helmet.contentSecurityPolicy({}));
app.use(helmet.contentSecurityPolicy(config));
app.use(helmet.contentSecurityPolicy({
directives: {
defaultSrc: ["'self'"]
defaultSrc: ["'self'"],
reportUri: reportUriCb,
'report-uri': reportUriCb,
reportTo: reportUriCb,
'report-to': reportUriCb
},
reportOnly: reportOnlyCb,
loose: false,
setAllHeaders: true
}));
+5 -5
View File
@@ -69,8 +69,8 @@ declare namespace helmet {
objectSrc?: HelmetCspDirectiveValue[];
pluginTypes?: HelmetCspDirectiveValue[];
prefetchSrc?: HelmetCspDirectiveValue[];
reportTo?: string;
reportUri?: string;
reportTo?: HelmetCspDirectiveValue;
reportUri?: HelmetCspDirectiveValue;
requireSriFor?: HelmetCspRequireSriForValue[];
sandbox?: HelmetCspSandboxDirective[];
scriptSrc?: HelmetCspDirectiveValue[];
@@ -95,8 +95,8 @@ declare namespace helmet {
'object-src'?: HelmetCspDirectiveValue[];
'plugin-types'?: HelmetCspDirectiveValue[];
'prefetch-src'?: HelmetCspDirectiveValue[];
'report-to'?: string;
'report-uri'?: string;
'report-to'?: HelmetCspDirectiveValue;
'report-uri'?: HelmetCspDirectiveValue;
'require-sri-for'?: HelmetCspRequireSriForValue[];
'sandbox'?: HelmetCspSandboxDirective[];
'script-src'?: HelmetCspDirectiveValue;
@@ -106,7 +106,7 @@ declare namespace helmet {
}
export interface IHelmetContentSecurityPolicyConfiguration {
reportOnly?: boolean;
reportOnly?: boolean | ((req: express.Request, res: express.Response) => boolean);
setAllHeaders?: boolean;
disableAndroid?: boolean;
browserSniff?: boolean;