fix: remove duplicate configuration for helmet-hsts

This commit is contained in:
Julian Lam
2020-08-03 20:40:44 -04:00
parent ad68a338c4
commit 0f10e0836b

View File

@@ -164,9 +164,7 @@ function setupExpressApp(app) {
saveUninitialized: nconf.get('sessionSaveUninitialized') || false,
}));
app.use(helmet({
hsts: !!meta.config['hsts-enabled'],
}));
app.use(helmet());
app.use(helmet.referrerPolicy({ policy: 'strict-origin-when-cross-origin' }));
if (meta.config['hsts-enabled']) {
app.use(helmet.hsts({