From 69a72b19f06e2774b7a92d83677a4c3b6e15aab8 Mon Sep 17 00:00:00 2001 From: Corbin Date: Sun, 19 Nov 2017 20:43:33 -0800 Subject: [PATCH 1/2] [lusca] Added typings --- types/lusca/index.d.ts | 77 ++++++++++++++++++++++++++++++++++++++ types/lusca/lusca-tests.ts | 24 ++++++++++++ types/lusca/tsconfig.json | 22 +++++++++++ types/lusca/tslint.json | 1 + 4 files changed, 124 insertions(+) create mode 100644 types/lusca/index.d.ts create mode 100644 types/lusca/lusca-tests.ts create mode 100644 types/lusca/tsconfig.json create mode 100644 types/lusca/tslint.json diff --git a/types/lusca/index.d.ts b/types/lusca/index.d.ts new file mode 100644 index 0000000000..c85e2d9d66 --- /dev/null +++ b/types/lusca/index.d.ts @@ -0,0 +1,77 @@ +// Type definitions for lusca 1.5 +// Project: https://github.com/krakenjs/lusca#readme +// Definitions by: Corbin Crutchley +// Definitions: https://github.com/DefinitelyTyped/DefinitelyTyped + +import express = require('express'); + +declare function lusca(options?: lusca.LuscaOptions): express.RequestHandler; + +declare namespace lusca { + /*~ Documentation declares that: + *~ Setting any value to false will disable it. + */ + interface LuscaOptions { + csrf?: csrfOptions | boolean; + csp?: cspOptions | false; + xframe?: string | false; + p3p?: string | false; + hsts?: hstsOptions | false; + xssProtection?: boolean; + nosniff?: boolean; + referrerPolicy?: string | false; + } + + interface cspOptions { + policy?: string | object | (object | string)[]; + reportOnly?: boolean; + reportUri?: string; + styleNonce?: boolean; + scriptNonce?: boolean; + } + + interface hstsOptions { + maxAge?: number; + includeSubDomains?: boolean; + preload?: boolean; + } + + type csrfOptions = csrfOptionsAngular | csrfOptionsNonAngular; + + interface csrfOptionsAngular { + key?: string; + secret?: string; + impl?: () => any; + cookie?: string | { + options?: object; + }; + angular: true; + } + + interface csrfOptionsNonAngular { + key?: string; + secret?: string; + impl?: () => any; + cookie?: string | { + name: string; + options?: object; + }; + angular?: false; + } + + interface xssProtectionOptions { + enabled?: boolean; + mode?: string; + } + + function csrf(options?: csrfOptions): express.RequestHandler; + function csp(options?: cspOptions): express.RequestHandler; + function xframe(value: string): express.RequestHandler; + function p3p(value: string): express.RequestHandler; + function hsts(options?: hstsOptions): express.RequestHandler; + function xssProtection(options?: xssProtectionOptions): express.RequestHandler; + function nosniff(): express.RequestHandler; + function referrerPolicy(value: string): express.RequestHandler; +} + +export = lusca; diff --git a/types/lusca/lusca-tests.ts b/types/lusca/lusca-tests.ts new file mode 100644 index 0000000000..5d267c0a95 --- /dev/null +++ b/types/lusca/lusca-tests.ts @@ -0,0 +1,24 @@ +import express = require('express'); +import lusca = require('lusca'); + +const app = express(); + +app.use(lusca({ + csrf: true, + csp: { policy: "referrer no-referrer"}, + xframe: 'SAMEORIGIN', + p3p: 'ABCDEF', + hsts: {maxAge: 31536000, includeSubDomains: true, preload: true}, + xssProtection: true, + nosniff: true, + referrerPolicy: 'same-origin' +})); +app.use(lusca.csrf()); +app.use(lusca.csp({policy: [{ "img-src": "'self' http:" }, "block-all-mixed-content"] + , reportOnly: false})); +app.use(lusca.xframe('SAMEORIGIN')); +app.use(lusca.p3p('ABCDEF')); +app.use(lusca.hsts({ maxAge: 31536000 })); +app.use(lusca.xssProtection(true)); +app.use(lusca.nosniff()); +app.use(lusca.referrerPolicy('same-origin')); diff --git a/types/lusca/tsconfig.json b/types/lusca/tsconfig.json new file mode 100644 index 0000000000..656795435c --- /dev/null +++ b/types/lusca/tsconfig.json @@ -0,0 +1,22 @@ +{ + "compilerOptions": { + "module": "commonjs", + "lib": [ + "es6" + ], + "noImplicitAny": true, + "noImplicitThis": true, + "strictNullChecks": true, + "baseUrl": "../", + "typeRoots": [ + "../" + ], + "types": [], + "noEmit": true, + "forceConsistentCasingInFileNames": true + }, + "files": [ + "index.d.ts", + "lusca-tests.ts" + ] +} diff --git a/types/lusca/tslint.json b/types/lusca/tslint.json new file mode 100644 index 0000000000..3db14f85ea --- /dev/null +++ b/types/lusca/tslint.json @@ -0,0 +1 @@ +{ "extends": "dtslint/dt.json" } From 9bb9e1b3d3f7c62d1694fddbfe7f9c8b58654053 Mon Sep 17 00:00:00 2001 From: Corbin Date: Sun, 19 Nov 2017 20:58:25 -0800 Subject: [PATCH 2/2] [lusca] Fix tests and linting --- types/lusca/index.d.ts | 7 ++++--- types/lusca/lusca-tests.ts | 4 ++-- types/lusca/tsconfig.json | 1 + 3 files changed, 7 insertions(+), 5 deletions(-) diff --git a/types/lusca/index.d.ts b/types/lusca/index.d.ts index c85e2d9d66..8527ef3411 100644 --- a/types/lusca/index.d.ts +++ b/types/lusca/index.d.ts @@ -2,6 +2,7 @@ // Project: https://github.com/krakenjs/lusca#readme // Definitions by: Corbin Crutchley // Definitions: https://github.com/DefinitelyTyped/DefinitelyTyped +// TypeScript Version: 2.2 import express = require('express'); @@ -17,13 +18,13 @@ declare namespace lusca { xframe?: string | false; p3p?: string | false; hsts?: hstsOptions | false; - xssProtection?: boolean; + xssProtection?: xssProtectionOptions | boolean; nosniff?: boolean; referrerPolicy?: string | false; } interface cspOptions { - policy?: string | object | (object | string)[]; + policy?: string | object | Array; reportOnly?: boolean; reportUri?: string; styleNonce?: boolean; @@ -69,7 +70,7 @@ declare namespace lusca { function xframe(value: string): express.RequestHandler; function p3p(value: string): express.RequestHandler; function hsts(options?: hstsOptions): express.RequestHandler; - function xssProtection(options?: xssProtectionOptions): express.RequestHandler; + function xssProtection(options?: xssProtectionOptions | true): express.RequestHandler; function nosniff(): express.RequestHandler; function referrerPolicy(value: string): express.RequestHandler; } diff --git a/types/lusca/lusca-tests.ts b/types/lusca/lusca-tests.ts index 5d267c0a95..8a74ec5e8a 100644 --- a/types/lusca/lusca-tests.ts +++ b/types/lusca/lusca-tests.ts @@ -13,9 +13,9 @@ app.use(lusca({ nosniff: true, referrerPolicy: 'same-origin' })); + app.use(lusca.csrf()); -app.use(lusca.csp({policy: [{ "img-src": "'self' http:" }, "block-all-mixed-content"] - , reportOnly: false})); +app.use(lusca.csp({policy: [{ "img-src": "'self' http:" }, "block-all-mixed-content"], reportOnly: false})); app.use(lusca.xframe('SAMEORIGIN')); app.use(lusca.p3p('ABCDEF')); app.use(lusca.hsts({ maxAge: 31536000 })); diff --git a/types/lusca/tsconfig.json b/types/lusca/tsconfig.json index 656795435c..ede7926c1c 100644 --- a/types/lusca/tsconfig.json +++ b/types/lusca/tsconfig.json @@ -7,6 +7,7 @@ "noImplicitAny": true, "noImplicitThis": true, "strictNullChecks": true, + "strictFunctionTypes": true, "baseUrl": "../", "typeRoots": [ "../"