Skip to content

SecurityHeadersOptions

Defined in: src/plugins/middleware/security-headers.ts:4

optional contentSecurityPolicy: boolean | Record<string, any>

Defined in: src/plugins/middleware/security-headers.ts:8

Content Security Policy


optional crossOriginEmbedderPolicy: boolean

Defined in: src/plugins/middleware/security-headers.ts:12

Cross-Origin Embedder Policy


optional crossOriginOpenerPolicy: boolean

Defined in: src/plugins/middleware/security-headers.ts:16

Cross-Origin Opener Policy


optional crossOriginResourcePolicy: boolean

Defined in: src/plugins/middleware/security-headers.ts:20

Cross-Origin Resource Policy


optional dnsPrefetchControl: boolean | { allow: boolean; }

Defined in: src/plugins/middleware/security-headers.ts:24

DNS Prefetch Control


optional expectCt: boolean | { enforce?: boolean; maxAge?: number; reportUri?: string; }

Defined in: src/plugins/middleware/security-headers.ts:28

Expect CT


optional frameguard: boolean | { action: "deny" | "sameorigin" | "allow-from"; domain?: string; }

Defined in: src/plugins/middleware/security-headers.ts:32

Frameguard


optional hidePoweredBy: boolean

Defined in: src/plugins/middleware/security-headers.ts:36

Hide Powered By


optional hsts: boolean | { includeSubDomains?: boolean; maxAge?: number; preload?: boolean; }

Defined in: src/plugins/middleware/security-headers.ts:40

HTTP Strict Transport Security


optional ieNoOpen: boolean

Defined in: src/plugins/middleware/security-headers.ts:44

IE No Open


optional noSniff: boolean

Defined in: src/plugins/middleware/security-headers.ts:48

No Sniff


optional originAgentCluster: boolean

Defined in: src/plugins/middleware/security-headers.ts:52

Origin Agent Cluster


optional permittedCrossDomainPolicies: boolean | { permittedPolicies: "none" | "all" | "master-only" | "by-content-type"; }

Defined in: src/plugins/middleware/security-headers.ts:56

Permitted Cross Domain Policies


optional referrerPolicy: boolean | { policy: string | string[]; }

Defined in: src/plugins/middleware/security-headers.ts:60

Referrer Policy


optional xssFilter: boolean

Defined in: src/plugins/middleware/security-headers.ts:64

X-XSS-Protection