From d69d65ea7434eee85db4b905f0852f4d8fa7ecce Mon Sep 17 00:00:00 2001 From: Cheng-Han, Wu Date: Tue, 15 Mar 2016 10:41:49 +0800 Subject: Updated to send hsts in https header --- app.js | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'app.js') diff --git a/app.js b/app.js index 9ab1e82a..e1330790 100644 --- a/app.js +++ b/app.js @@ -17,6 +17,7 @@ var imgur = require('imgur'); var formidable = require('formidable'); var morgan = require('morgan'); var passportSocketIo = require("passport.socketio"); +var helmet = require('helmet'); //core var config = require("./config.js"); @@ -92,6 +93,13 @@ var sessionStore = new MongoStore({ //compression app.use(compression()); +// use hsts to tell https users stick to this +app.use(helmet.hsts({ + maxAge: 31536000 * 1000, // 365 days + includeSubdomains: true, + preload: true +})); + //session app.use(session({ name: config.sessionname, -- cgit v1.2.3