From 5d2d3ec875310de07fe79ae605dfbc0f1df585c5 Mon Sep 17 00:00:00 2001 From: Literallie Date: Wed, 18 Oct 2017 17:45:57 +0200 Subject: CSP: Upgrade insecure requests if possible Config option; default is to only upgrade if usessl --- app.js | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'app.js') diff --git a/app.js b/app.js index 54ec6cf7..8af029e7 100644 --- a/app.js +++ b/app.js @@ -126,6 +126,11 @@ if (config.csp.enable) { directives[propertyName] = directive; } } + if(config.csp.upgradeInsecureRequests === 'auto') { + directives.upgradeInsecureRequests = config.usessl === 'true' + } else { + directives.upgradeInsecureRequests = config.csp.upgradeInsecureRequests === 'true' + } app.use(helmet.contentSecurityPolicy({ directives: directives })) -- cgit v1.2.3