fix(server): adds XFrameOptions and ContentSecurityPolicy headers
This commit is contained in:
@@ -92,6 +92,8 @@ app.Use(async (context, next) =>
|
|||||||
context.Response.Headers.AccessControlAllowOrigin = "*";
|
context.Response.Headers.AccessControlAllowOrigin = "*";
|
||||||
context.Response.Headers.AccessControlAllowMethods = "GET, POST, PUT, DELETE, PATCH, OPTIONS";
|
context.Response.Headers.AccessControlAllowMethods = "GET, POST, PUT, DELETE, PATCH, OPTIONS";
|
||||||
context.Response.Headers.AccessControlAllowHeaders = "Content-Type, Authorization";
|
context.Response.Headers.AccessControlAllowHeaders = "Content-Type, Authorization";
|
||||||
|
context.Response.Headers.XFrameOptions = "DENY";
|
||||||
|
context.Response.Headers.ContentSecurityPolicy = "frame-ancestors 'none'";
|
||||||
|
|
||||||
if (HttpMethods.IsOptions(context.Request.Method))
|
if (HttpMethods.IsOptions(context.Request.Method))
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user