Skip to content
This repository has been archived by the owner on May 3, 2024. It is now read-only.

Commit

Permalink
feat: update strict transport security header to 2 years (#1164)
Browse files Browse the repository at this point in the history
  • Loading branch information
Matthew-Mallimo authored Oct 30, 2023
1 parent 273f64b commit dcaa34b
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion __tests__/server/middleware/addSecurityHeaders.spec.js
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ describe('addSecurityHeaders', () => {
const securityHeaders = {
'X-Frame-Options': 'DENY',
'X-Content-Type-Options': 'nosniff',
'Strict-Transport-Security': 'max-age=15552000; includeSubDomains',
'Strict-Transport-Security': 'max-age=63072000; includeSubDomains',
'X-XSS-Protection': '1; mode=block',
'Referrer-Policy': 'same-origin',
};
Expand Down
2 changes: 1 addition & 1 deletion src/server/middleware/addSecurityHeaders.js
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
export default function addSecurityHeaders(req, res, next) {
res.set('X-Frame-Options', 'DENY');
res.set('X-Content-Type-Options', 'nosniff');
res.set('Strict-Transport-Security', 'max-age=15552000; includeSubDomains');
res.set('Strict-Transport-Security', 'max-age=63072000; includeSubDomains');
res.set('X-XSS-Protection', '1; mode=block');
res.set('Referrer-Policy', process.env.ONE_REFERRER_POLICY_OVERRIDE || 'same-origin');
next();
Expand Down

0 comments on commit dcaa34b

Please sign in to comment.