fix(server): use csp to imporve security

This commit is contained in:
syuilo 2021-08-24 13:08:20 +09:00
parent c8de4d6a11
commit ea97cd7c14
3 changed files with 9 additions and 0 deletions

View File

@ -13,6 +13,7 @@
- クライアントのデザインの調整 - クライアントのデザインの調整
### Bugfixes ### Bugfixes
- セキュリティの向上
## 12.89.0 (2021/08/21) ## 12.89.0 (2021/08/21)

View File

@ -17,6 +17,10 @@ const _dirname = dirname(_filename);
// Init app // Init app
const app = new Koa(); const app = new Koa();
app.use(cors()); app.use(cors());
app.use(async (ctx, next) => {
ctx.set('Content-Security-Policy', `default-src 'none'; style-src 'unsafe-inline'`);
await next();
});
// Init router // Init router
const router = new Router(); const router = new Router();

View File

@ -10,6 +10,10 @@ import { proxyMedia } from './proxy-media';
// Init app // Init app
const app = new Koa(); const app = new Koa();
app.use(cors()); app.use(cors());
app.use(async (ctx, next) => {
ctx.set('Content-Security-Policy', `default-src 'none'; style-src 'unsafe-inline'`);
await next();
});
// Init router // Init router
const router = new Router(); const router = new Router();