diff --git a/types/helmet/helmet-tests.ts b/types/helmet/helmet-tests.ts index 59e5613408..8b4c5634ac 100644 --- a/types/helmet/helmet-tests.ts +++ b/types/helmet/helmet-tests.ts @@ -58,13 +58,21 @@ function contentSecurityPolicyTest() { disableAndroid: false }; + function reportUriCb(req: express.Request, res: express.Response) { return '/some-uri'; } + function reportOnlyCb(req: express.Request, res: express.Response) { return false; } + app.use(helmet.contentSecurityPolicy()); app.use(helmet.contentSecurityPolicy({})); app.use(helmet.contentSecurityPolicy(config)); app.use(helmet.contentSecurityPolicy({ directives: { - defaultSrc: ["'self'"] + defaultSrc: ["'self'"], + reportUri: reportUriCb, + 'report-uri': reportUriCb, + reportTo: reportUriCb, + 'report-to': reportUriCb }, + reportOnly: reportOnlyCb, loose: false, setAllHeaders: true })); diff --git a/types/helmet/index.d.ts b/types/helmet/index.d.ts index 3625d029a0..b0a50c901e 100644 --- a/types/helmet/index.d.ts +++ b/types/helmet/index.d.ts @@ -69,8 +69,8 @@ declare namespace helmet { objectSrc?: HelmetCspDirectiveValue[]; pluginTypes?: HelmetCspDirectiveValue[]; prefetchSrc?: HelmetCspDirectiveValue[]; - reportTo?: string; - reportUri?: string; + reportTo?: HelmetCspDirectiveValue; + reportUri?: HelmetCspDirectiveValue; requireSriFor?: HelmetCspRequireSriForValue[]; sandbox?: HelmetCspSandboxDirective[]; scriptSrc?: HelmetCspDirectiveValue[]; @@ -95,8 +95,8 @@ declare namespace helmet { 'object-src'?: HelmetCspDirectiveValue[]; 'plugin-types'?: HelmetCspDirectiveValue[]; 'prefetch-src'?: HelmetCspDirectiveValue[]; - 'report-to'?: string; - 'report-uri'?: string; + 'report-to'?: HelmetCspDirectiveValue; + 'report-uri'?: HelmetCspDirectiveValue; 'require-sri-for'?: HelmetCspRequireSriForValue[]; 'sandbox'?: HelmetCspSandboxDirective[]; 'script-src'?: HelmetCspDirectiveValue; @@ -106,7 +106,7 @@ declare namespace helmet { } export interface IHelmetContentSecurityPolicyConfiguration { - reportOnly?: boolean; + reportOnly?: boolean | ((req: express.Request, res: express.Response) => boolean); setAllHeaders?: boolean; disableAndroid?: boolean; browserSniff?: boolean;