Properly added pwndpasswords API to CSP

This commit is contained in:
Joel Biddle
2023-08-22 17:58:10 +10:00
parent 196beb8355
commit e288402ec4
2 changed files with 26 additions and 35 deletions
+1 -10
View File
@@ -132,16 +132,7 @@ const main = async () => {
// in production // in production
app.disable("x-powered-by"); app.disable("x-powered-by");
app.use(apiLimiter); app.use(apiLimiter);
app.use( app.use(helmet());
helmet.contentSecurityPolicy({
useDefaults: true,
directives: {
defaultSrc: ["'self'"],
imgSrc: ["*", "data:"],
connectSrc: ["'self'", "https://api.pwnedpasswords.com/range/"]
}
})
);
} }
app.use((req, res, next) => { app.use((req, res, next) => {
+25 -25
View File
@@ -3,7 +3,7 @@
/** /**
* @type {import('next').NextConfig} * @type {import('next').NextConfig}
**/ **/
const path = require('path'); const path = require("path");
const ContentSecurityPolicy = ` const ContentSecurityPolicy = `
default-src 'self'; default-src 'self';
@@ -11,7 +11,7 @@ const ContentSecurityPolicy = `
style-src 'self' https://rsms.me 'unsafe-inline'; style-src 'self' https://rsms.me 'unsafe-inline';
child-src https://api.stripe.com; child-src https://api.stripe.com;
frame-src https://js.stripe.com/ https://api.stripe.com https://www.youtube.com/; frame-src https://js.stripe.com/ https://api.stripe.com https://www.youtube.com/;
connect-src 'self' wss://nexus-websocket-a.intercom.io https://api-iam.intercom.io https://api.heroku.com/ https://id.heroku.com/oauth/authorize https://id.heroku.com/oauth/token https://checkout.stripe.com https://app.posthog.com https://api.stripe.com http://localhost:*; connect-src 'self' wss://nexus-websocket-a.intercom.io https://api-iam.intercom.io https://api.heroku.com/ https://id.heroku.com/oauth/authorize https://id.heroku.com/oauth/token https://checkout.stripe.com https://app.posthog.com https://api.stripe.com https://api.pwnedpasswords.com http://localhost:*;
img-src 'self' https://static.intercomassets.com https://js.intercomcdn.com https://downloads.intercomcdn.com https://*.stripe.com https://i.ytimg.com/ data:; img-src 'self' https://static.intercomassets.com https://js.intercomcdn.com https://downloads.intercomcdn.com https://*.stripe.com https://i.ytimg.com/ data:;
media-src https://js.intercomcdn.com; media-src https://js.intercomcdn.com;
font-src 'self' https://fonts.intercomcdn.com/ https://maxcdn.bootstrapcdn.com https://rsms.me https://fonts.gstatic.com; font-src 'self' https://fonts.intercomcdn.com/ https://maxcdn.bootstrapcdn.com https://rsms.me https://fonts.gstatic.com;
@@ -21,50 +21,50 @@ const ContentSecurityPolicy = `
// after learning more below. // after learning more below.
const securityHeaders = [ const securityHeaders = [
{ {
key: 'X-DNS-Prefetch-Control', key: "X-DNS-Prefetch-Control",
value: 'on' value: "on"
}, },
{ {
key: 'Strict-Transport-Security', key: "Strict-Transport-Security",
value: 'max-age=63072000; includeSubDomains; preload' value: "max-age=63072000; includeSubDomains; preload"
}, },
{ {
key: 'X-XSS-Protection', key: "X-XSS-Protection",
value: '1; mode=block' value: "1; mode=block"
}, },
{ {
key: 'X-Frame-Options', key: "X-Frame-Options",
value: 'SAMEORIGIN' value: "SAMEORIGIN"
}, },
{ {
key: 'Permissions-Policy', key: "Permissions-Policy",
value: 'camera=(), microphone=()' value: "camera=(), microphone=()"
}, },
{ {
key: 'X-Content-Type-Options', key: "X-Content-Type-Options",
value: 'nosniff' value: "nosniff"
}, },
{ {
key: 'Referrer-Policy', key: "Referrer-Policy",
value: 'strict-origin-when-cross-origin' value: "strict-origin-when-cross-origin"
}, },
{ {
key: 'Content-Security-Policy', key: "Content-Security-Policy",
value: ContentSecurityPolicy.replace(/\s{2,}/g, ' ').trim() value: ContentSecurityPolicy.replace(/\s{2,}/g, " ").trim()
} }
]; ];
module.exports = { module.exports = {
output: 'standalone', output: "standalone",
i18n: { i18n: {
locales: ['en', 'ko', 'fr', 'pt-BR', 'pt-PT', 'es'], locales: ["en", "ko", "fr", "pt-BR", "pt-PT", "es"],
defaultLocale: 'en' defaultLocale: "en"
}, },
async headers() { async headers() {
return [ return [
{ {
// Apply these headers to all routes in your application. // Apply these headers to all routes in your application.
source: '/:path*', source: "/:path*",
headers: securityHeaders headers: securityHeaders
} }
]; ];
@@ -73,15 +73,15 @@ module.exports = {
// config // config
config.module.rules.push({ config.module.rules.push({
test: /\.wasm$/, test: /\.wasm$/,
loader: 'base64-loader', loader: "base64-loader",
type: 'javascript/auto' type: "javascript/auto"
}); });
config.module.noParse = /\.wasm$/; config.module.noParse = /\.wasm$/;
config.module.rules.forEach((rule) => { config.module.rules.forEach((rule) => {
(rule.oneOf || []).forEach((oneOf) => { (rule.oneOf || []).forEach((oneOf) => {
if (oneOf.loader && oneOf.loader.indexOf('file-loader') >= 0) { if (oneOf.loader && oneOf.loader.indexOf("file-loader") >= 0) {
oneOf.exclude.push(/\.wasm$/); oneOf.exclude.push(/\.wasm$/);
} }
}); });