This commit is contained in:
+10
-3
@@ -590,6 +590,13 @@ function conflict(database: DatabaseContext, id: string): never {
|
||||
}
|
||||
|
||||
export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
// Helmet's defaults include `upgrade-insecure-requests`, HSTS, COOP and
|
||||
// Origin-Agent-Cluster. Those headers are appropriate for HTTPS, but an
|
||||
// explicitly opted-in HTTP deployment must remain HTTP all the way through
|
||||
// the asset graph; otherwise browsers upgrade `/assets/*` to HTTPS and the
|
||||
// plain HTTP listener appears as a blank page. Keep the transport-sensitive
|
||||
// headers protocol-aware while retaining the other hardening headers.
|
||||
const secureOrigin = config.publicOrigin.startsWith("https:");
|
||||
const app = Fastify({
|
||||
logger: config.isProduction ? { level: "info", redact: ["req.headers.cookie", "req.headers.x-csrf-token", "password", "temporaryPassword"] } : false,
|
||||
// Fastify's runtime accepts a numeric hop count, while its v5 typings do
|
||||
@@ -604,10 +611,10 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
|
||||
await app.register(cookie);
|
||||
await app.register(helmet, {
|
||||
...(config.isLocalOrigin ? { hsts: false } : {}),
|
||||
...(!secureOrigin || config.isLocalOrigin ? { hsts: false } : {}),
|
||||
frameguard: { action: "deny" },
|
||||
referrerPolicy: { policy: "no-referrer" },
|
||||
crossOriginOpenerPolicy: { policy: "same-origin" },
|
||||
...(secureOrigin ? { crossOriginOpenerPolicy: { policy: "same-origin" }, originAgentCluster: true } : { crossOriginOpenerPolicy: false, originAgentCluster: false }),
|
||||
crossOriginResourcePolicy: { policy: "same-origin" },
|
||||
contentSecurityPolicy: {
|
||||
directives: {
|
||||
@@ -618,7 +625,7 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
"frame-ancestors": ["'none'"],
|
||||
"base-uri": ["'none'"],
|
||||
"form-action": ["'self'"],
|
||||
...(config.isLocalOrigin ? { "upgrade-insecure-requests": null } : {}),
|
||||
...(!secureOrigin ? { "upgrade-insecure-requests": null } : {}),
|
||||
},
|
||||
},
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user