From b00f63244b3d734ccf57a5ca74dee225a7af03f7 Mon Sep 17 00:00:00 2001 From: minggas Date: Thu, 13 Jun 2019 19:09:52 -0300 Subject: [PATCH 1/2] fix: require helmet --- server.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server.js b/server.js index ddc20a0..a45f0b0 100644 --- a/server.js +++ b/server.js @@ -3,7 +3,7 @@ var express = require('express'); var bodyParser = require('body-parser'); var cors = require('cors'); - +var helmet = require('helmet'); var apiRoutes = require('./routes/api.js'); var fccTestingRoutes = require('./routes/fcctesting.js'); var runner = require('./test-runner'); From f15f50c6f54809d5e660271ff2370bbe1669b0f4 Mon Sep 17 00:00:00 2001 From: minggas Date: Thu, 13 Jun 2019 19:10:54 -0300 Subject: [PATCH 2/2] fix: use (no cache, hidePoweredBy and xssFilter) --- server.js | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/server.js b/server.js index a45f0b0..2d96c09 100644 --- a/server.js +++ b/server.js @@ -16,6 +16,11 @@ app.use(cors({origin: '*'})); //USED FOR FCC TESTING PURPOSES ONLY! app.use(bodyParser.json()); app.use(bodyParser.urlencoded({ extended: true })); +app.use( helmet( { + noCache : true, + hidePoweredBy : { setTo: 'PHP 4.2.0' }, + xssFilter : true, +} ) ); //Index page (static HTML) app.route('/')