mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-11-03 04:25:55 +01:00
dep: closes #11577
Breaking: Cross-Origin-Embedder-Policy middleware is now disabled by default. See #411
This commit is contained in:
@@ -192,11 +192,9 @@ function setupHelmet(app) {
|
||||
crossOriginOpenerPolicy: { policy: meta.config['cross-origin-opener-policy'] },
|
||||
crossOriginResourcePolicy: { policy: meta.config['cross-origin-resource-policy'] },
|
||||
referrerPolicy: { policy: 'strict-origin-when-cross-origin' },
|
||||
crossOriginEmbedderPolicy: !!meta.config['cross-origin-embedder-policy'],
|
||||
};
|
||||
|
||||
if (!meta.config['cross-origin-embedder-policy']) {
|
||||
options.crossOriginEmbedderPolicy = false;
|
||||
}
|
||||
if (meta.config['hsts-enabled']) {
|
||||
options.hsts = {
|
||||
maxAge: meta.config['hsts-maxage'],
|
||||
|
||||
Reference in New Issue
Block a user