From 57aa073bfcaac4f5f021268ae42e4e13413e15d3 Mon Sep 17 00:00:00 2001 From: Anto Christopher <93177734+anto-deepsource@users.noreply.github.com> Date: Fri, 5 Apr 2024 12:27:42 +0530 Subject: [PATCH] Update server.js --- server.js | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/server.js b/server.js index 2e00d0f7..cee4031e 100644 --- a/server.js +++ b/server.js @@ -1,10 +1,15 @@ const express = require('express'); const request = require('request'); // request is deprecated. Prefer using `axios` instead const helmet = require('helmet') - - -const app = express(); // Sensitive - +const app = express(); +app.use( + helmet.contentSecurityPolicy({ + directives: { + // other directives + "frame-ancestors": ["'example.com'"] + } + }) +); app.use( helmet.expectCt({