proposed fix for missing callback type for reportUri/reportTo

This commit is contained in:
Daniel Rentz
2018-09-24 11:11:34 +02:00
parent adf4e18eef
commit 88383bb3f9
2 changed files with 11 additions and 5 deletions
+7 -1
View File
@@ -58,12 +58,18 @@ function contentSecurityPolicyTest() {
disableAndroid: false
};
function reportCb(req: express.Request, res: express.Response) { return '/some-uri'; }
app.use(helmet.contentSecurityPolicy());
app.use(helmet.contentSecurityPolicy({}));
app.use(helmet.contentSecurityPolicy(config));
app.use(helmet.contentSecurityPolicy({
directives: {
defaultSrc: ["'self'"]
defaultSrc: ["'self'"],
reportUri: reportCb,
'report-uri': reportCb,
reportTo: reportCb,
'report-to': reportCb
},
loose: false,
setAllHeaders: true
+4 -4
View File
@@ -69,8 +69,8 @@ declare namespace helmet {
objectSrc?: HelmetCspDirectiveValue[];
pluginTypes?: HelmetCspDirectiveValue[];
prefetchSrc?: HelmetCspDirectiveValue[];
reportTo?: string;
reportUri?: string;
reportTo?: HelmetCspDirectiveValue;
reportUri?: HelmetCspDirectiveValue;
requireSriFor?: HelmetCspRequireSriForValue[];
sandbox?: HelmetCspSandboxDirective[];
scriptSrc?: HelmetCspDirectiveValue[];
@@ -95,8 +95,8 @@ declare namespace helmet {
'object-src'?: HelmetCspDirectiveValue[];
'plugin-types'?: HelmetCspDirectiveValue[];
'prefetch-src'?: HelmetCspDirectiveValue[];
'report-to'?: string;
'report-uri'?: string;
'report-to'?: HelmetCspDirectiveValue;
'report-uri'?: HelmetCspDirectiveValue;
'require-sri-for'?: HelmetCspRequireSriForValue[];
'sandbox'?: HelmetCspSandboxDirective[];
'script-src'?: HelmetCspDirectiveValue;