From 88383bb3f93efe8fbcf19d6ff07bcb63a8162fd6 Mon Sep 17 00:00:00 2001 From: Daniel Rentz Date: Mon, 24 Sep 2018 11:11:34 +0200 Subject: [PATCH 1/4] proposed fix for missing callback type for reportUri/reportTo --- types/helmet/helmet-tests.ts | 8 +++++++- types/helmet/index.d.ts | 8 ++++---- 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/types/helmet/helmet-tests.ts b/types/helmet/helmet-tests.ts index 59e5613408..1ec548e49b 100644 --- a/types/helmet/helmet-tests.ts +++ b/types/helmet/helmet-tests.ts @@ -58,12 +58,18 @@ function contentSecurityPolicyTest() { disableAndroid: false }; + function reportCb(req: express.Request, res: express.Response) { return '/some-uri'; } + app.use(helmet.contentSecurityPolicy()); app.use(helmet.contentSecurityPolicy({})); app.use(helmet.contentSecurityPolicy(config)); app.use(helmet.contentSecurityPolicy({ directives: { - defaultSrc: ["'self'"] + defaultSrc: ["'self'"], + reportUri: reportCb, + 'report-uri': reportCb, + reportTo: reportCb, + 'report-to': reportCb }, loose: false, setAllHeaders: true diff --git a/types/helmet/index.d.ts b/types/helmet/index.d.ts index 3625d029a0..bdee793cdb 100644 --- a/types/helmet/index.d.ts +++ b/types/helmet/index.d.ts @@ -69,8 +69,8 @@ declare namespace helmet { objectSrc?: HelmetCspDirectiveValue[]; pluginTypes?: HelmetCspDirectiveValue[]; prefetchSrc?: HelmetCspDirectiveValue[]; - reportTo?: string; - reportUri?: string; + reportTo?: HelmetCspDirectiveValue; + reportUri?: HelmetCspDirectiveValue; requireSriFor?: HelmetCspRequireSriForValue[]; sandbox?: HelmetCspSandboxDirective[]; scriptSrc?: HelmetCspDirectiveValue[]; @@ -95,8 +95,8 @@ declare namespace helmet { 'object-src'?: HelmetCspDirectiveValue[]; 'plugin-types'?: HelmetCspDirectiveValue[]; 'prefetch-src'?: HelmetCspDirectiveValue[]; - 'report-to'?: string; - 'report-uri'?: string; + 'report-to'?: HelmetCspDirectiveValue; + 'report-uri'?: HelmetCspDirectiveValue; 'require-sri-for'?: HelmetCspRequireSriForValue[]; 'sandbox'?: HelmetCspSandboxDirective[]; 'script-src'?: HelmetCspDirectiveValue; From 98fb32f24bf6c53c5d9c1d928ac1dce138a67369 Mon Sep 17 00:00:00 2001 From: Daniel Rentz Date: Mon, 24 Sep 2018 14:15:41 +0200 Subject: [PATCH 2/4] missing callback type for reportOnly --- types/helmet/helmet-tests.ts | 12 +++++++----- types/helmet/index.d.ts | 6 +++++- 2 files changed, 12 insertions(+), 6 deletions(-) diff --git a/types/helmet/helmet-tests.ts b/types/helmet/helmet-tests.ts index 1ec548e49b..8b4c5634ac 100644 --- a/types/helmet/helmet-tests.ts +++ b/types/helmet/helmet-tests.ts @@ -58,7 +58,8 @@ function contentSecurityPolicyTest() { disableAndroid: false }; - function reportCb(req: express.Request, res: express.Response) { return '/some-uri'; } + function reportUriCb(req: express.Request, res: express.Response) { return '/some-uri'; } + function reportOnlyCb(req: express.Request, res: express.Response) { return false; } app.use(helmet.contentSecurityPolicy()); app.use(helmet.contentSecurityPolicy({})); @@ -66,11 +67,12 @@ function contentSecurityPolicyTest() { app.use(helmet.contentSecurityPolicy({ directives: { defaultSrc: ["'self'"], - reportUri: reportCb, - 'report-uri': reportCb, - reportTo: reportCb, - 'report-to': reportCb + reportUri: reportUriCb, + 'report-uri': reportUriCb, + reportTo: reportUriCb, + 'report-to': reportUriCb }, + reportOnly: reportOnlyCb, loose: false, setAllHeaders: true })); diff --git a/types/helmet/index.d.ts b/types/helmet/index.d.ts index bdee793cdb..c5048d390f 100644 --- a/types/helmet/index.d.ts +++ b/types/helmet/index.d.ts @@ -105,8 +105,12 @@ declare namespace helmet { 'worker-src'?: HelmetCspDirectiveValue; } + export interface IHelmetContentSecurityReportOnlyFunction { + (req: express.Request, res: express.Response): boolean; + } + export interface IHelmetContentSecurityPolicyConfiguration { - reportOnly?: boolean; + reportOnly?: boolean | IHelmetContentSecurityReportOnlyFunction; setAllHeaders?: boolean; disableAndroid?: boolean; browserSniff?: boolean; From 120fd43ea01f7e9fcdb914514fafa41a2087a0f8 Mon Sep 17 00:00:00 2001 From: Daniel Rentz Date: Mon, 24 Sep 2018 14:55:59 +0200 Subject: [PATCH 3/4] "false" is also valid --- types/helmet/helmet-tests.ts | 8 ++++++++ types/helmet/index.d.ts | 8 ++++---- 2 files changed, 12 insertions(+), 4 deletions(-) diff --git a/types/helmet/helmet-tests.ts b/types/helmet/helmet-tests.ts index 8b4c5634ac..2c5d582928 100644 --- a/types/helmet/helmet-tests.ts +++ b/types/helmet/helmet-tests.ts @@ -76,6 +76,14 @@ function contentSecurityPolicyTest() { loose: false, setAllHeaders: true })); + app.use(helmet.contentSecurityPolicy({ + directives: { + reportUri: false, + 'report-uri': false, + reportTo: false, + 'report-to': false + } + })); } /** diff --git a/types/helmet/index.d.ts b/types/helmet/index.d.ts index c5048d390f..69b0b7993a 100644 --- a/types/helmet/index.d.ts +++ b/types/helmet/index.d.ts @@ -69,8 +69,8 @@ declare namespace helmet { objectSrc?: HelmetCspDirectiveValue[]; pluginTypes?: HelmetCspDirectiveValue[]; prefetchSrc?: HelmetCspDirectiveValue[]; - reportTo?: HelmetCspDirectiveValue; - reportUri?: HelmetCspDirectiveValue; + reportTo?: HelmetCspDirectiveValue | false; + reportUri?: HelmetCspDirectiveValue | false; requireSriFor?: HelmetCspRequireSriForValue[]; sandbox?: HelmetCspSandboxDirective[]; scriptSrc?: HelmetCspDirectiveValue[]; @@ -95,8 +95,8 @@ declare namespace helmet { 'object-src'?: HelmetCspDirectiveValue[]; 'plugin-types'?: HelmetCspDirectiveValue[]; 'prefetch-src'?: HelmetCspDirectiveValue[]; - 'report-to'?: HelmetCspDirectiveValue; - 'report-uri'?: HelmetCspDirectiveValue; + 'report-to'?: HelmetCspDirectiveValue | false; + 'report-uri'?: HelmetCspDirectiveValue | false; 'require-sri-for'?: HelmetCspRequireSriForValue[]; 'sandbox'?: HelmetCspSandboxDirective[]; 'script-src'?: HelmetCspDirectiveValue; From a29098b806ec04c7a954f27a4a668b797d83d4a0 Mon Sep 17 00:00:00 2001 From: Daniel Rentz Date: Mon, 24 Sep 2018 16:49:39 +0200 Subject: [PATCH 4/4] suggested simplifications --- types/helmet/helmet-tests.ts | 8 -------- types/helmet/index.d.ts | 14 +++++--------- 2 files changed, 5 insertions(+), 17 deletions(-) diff --git a/types/helmet/helmet-tests.ts b/types/helmet/helmet-tests.ts index 2c5d582928..8b4c5634ac 100644 --- a/types/helmet/helmet-tests.ts +++ b/types/helmet/helmet-tests.ts @@ -76,14 +76,6 @@ function contentSecurityPolicyTest() { loose: false, setAllHeaders: true })); - app.use(helmet.contentSecurityPolicy({ - directives: { - reportUri: false, - 'report-uri': false, - reportTo: false, - 'report-to': false - } - })); } /** diff --git a/types/helmet/index.d.ts b/types/helmet/index.d.ts index 69b0b7993a..b0a50c901e 100644 --- a/types/helmet/index.d.ts +++ b/types/helmet/index.d.ts @@ -69,8 +69,8 @@ declare namespace helmet { objectSrc?: HelmetCspDirectiveValue[]; pluginTypes?: HelmetCspDirectiveValue[]; prefetchSrc?: HelmetCspDirectiveValue[]; - reportTo?: HelmetCspDirectiveValue | false; - reportUri?: HelmetCspDirectiveValue | false; + reportTo?: HelmetCspDirectiveValue; + reportUri?: HelmetCspDirectiveValue; requireSriFor?: HelmetCspRequireSriForValue[]; sandbox?: HelmetCspSandboxDirective[]; scriptSrc?: HelmetCspDirectiveValue[]; @@ -95,8 +95,8 @@ declare namespace helmet { 'object-src'?: HelmetCspDirectiveValue[]; 'plugin-types'?: HelmetCspDirectiveValue[]; 'prefetch-src'?: HelmetCspDirectiveValue[]; - 'report-to'?: HelmetCspDirectiveValue | false; - 'report-uri'?: HelmetCspDirectiveValue | false; + 'report-to'?: HelmetCspDirectiveValue; + 'report-uri'?: HelmetCspDirectiveValue; 'require-sri-for'?: HelmetCspRequireSriForValue[]; 'sandbox'?: HelmetCspSandboxDirective[]; 'script-src'?: HelmetCspDirectiveValue; @@ -105,12 +105,8 @@ declare namespace helmet { 'worker-src'?: HelmetCspDirectiveValue; } - export interface IHelmetContentSecurityReportOnlyFunction { - (req: express.Request, res: express.Response): boolean; - } - export interface IHelmetContentSecurityPolicyConfiguration { - reportOnly?: boolean | IHelmetContentSecurityReportOnlyFunction; + reportOnly?: boolean | ((req: express.Request, res: express.Response) => boolean); setAllHeaders?: boolean; disableAndroid?: boolean; browserSniff?: boolean;