diff --git a/types/lusca/index.d.ts b/types/lusca/index.d.ts new file mode 100644 index 0000000000..8527ef3411 --- /dev/null +++ b/types/lusca/index.d.ts @@ -0,0 +1,78 @@ +// Type definitions for lusca 1.5 +// Project: https://github.com/krakenjs/lusca#readme +// Definitions by: Corbin Crutchley +// Definitions: https://github.com/DefinitelyTyped/DefinitelyTyped +// TypeScript Version: 2.2 + +import express = require('express'); + +declare function lusca(options?: lusca.LuscaOptions): express.RequestHandler; + +declare namespace lusca { + /*~ Documentation declares that: + *~ Setting any value to false will disable it. + */ + interface LuscaOptions { + csrf?: csrfOptions | boolean; + csp?: cspOptions | false; + xframe?: string | false; + p3p?: string | false; + hsts?: hstsOptions | false; + xssProtection?: xssProtectionOptions | boolean; + nosniff?: boolean; + referrerPolicy?: string | false; + } + + interface cspOptions { + policy?: string | object | Array; + reportOnly?: boolean; + reportUri?: string; + styleNonce?: boolean; + scriptNonce?: boolean; + } + + interface hstsOptions { + maxAge?: number; + includeSubDomains?: boolean; + preload?: boolean; + } + + type csrfOptions = csrfOptionsAngular | csrfOptionsNonAngular; + + interface csrfOptionsAngular { + key?: string; + secret?: string; + impl?: () => any; + cookie?: string | { + options?: object; + }; + angular: true; + } + + interface csrfOptionsNonAngular { + key?: string; + secret?: string; + impl?: () => any; + cookie?: string | { + name: string; + options?: object; + }; + angular?: false; + } + + interface xssProtectionOptions { + enabled?: boolean; + mode?: string; + } + + function csrf(options?: csrfOptions): express.RequestHandler; + function csp(options?: cspOptions): express.RequestHandler; + function xframe(value: string): express.RequestHandler; + function p3p(value: string): express.RequestHandler; + function hsts(options?: hstsOptions): express.RequestHandler; + function xssProtection(options?: xssProtectionOptions | true): express.RequestHandler; + function nosniff(): express.RequestHandler; + function referrerPolicy(value: string): express.RequestHandler; +} + +export = lusca; diff --git a/types/lusca/lusca-tests.ts b/types/lusca/lusca-tests.ts new file mode 100644 index 0000000000..8a74ec5e8a --- /dev/null +++ b/types/lusca/lusca-tests.ts @@ -0,0 +1,24 @@ +import express = require('express'); +import lusca = require('lusca'); + +const app = express(); + +app.use(lusca({ + csrf: true, + csp: { policy: "referrer no-referrer"}, + xframe: 'SAMEORIGIN', + p3p: 'ABCDEF', + hsts: {maxAge: 31536000, includeSubDomains: true, preload: true}, + xssProtection: true, + nosniff: true, + referrerPolicy: 'same-origin' +})); + +app.use(lusca.csrf()); +app.use(lusca.csp({policy: [{ "img-src": "'self' http:" }, "block-all-mixed-content"], reportOnly: false})); +app.use(lusca.xframe('SAMEORIGIN')); +app.use(lusca.p3p('ABCDEF')); +app.use(lusca.hsts({ maxAge: 31536000 })); +app.use(lusca.xssProtection(true)); +app.use(lusca.nosniff()); +app.use(lusca.referrerPolicy('same-origin')); diff --git a/types/lusca/tsconfig.json b/types/lusca/tsconfig.json new file mode 100644 index 0000000000..ede7926c1c --- /dev/null +++ b/types/lusca/tsconfig.json @@ -0,0 +1,23 @@ +{ + "compilerOptions": { + "module": "commonjs", + "lib": [ + "es6" + ], + "noImplicitAny": true, + "noImplicitThis": true, + "strictNullChecks": true, + "strictFunctionTypes": true, + "baseUrl": "../", + "typeRoots": [ + "../" + ], + "types": [], + "noEmit": true, + "forceConsistentCasingInFileNames": true + }, + "files": [ + "index.d.ts", + "lusca-tests.ts" + ] +} diff --git a/types/lusca/tslint.json b/types/lusca/tslint.json new file mode 100644 index 0000000000..3db14f85ea --- /dev/null +++ b/types/lusca/tslint.json @@ -0,0 +1 @@ +{ "extends": "dtslint/dt.json" }