sanket3280/code-execution
0
1/**2 * Security Middleware3 * Additional security measures beyond helmet4 */5 6/**7 * Remove sensitive headers from responses8 */9function removeServerHeader(_req, res, next) {10 res.removeHeader('X-Powered-By');11 res.removeHeader('Server');12 next();13}14 15/**16 * Add custom security headers17 */18function addSecurityHeaders(_req, res, next) {19 // Prevent clickjacking20 res.setHeader('X-Frame-Options', 'DENY');21 22 // Prevent MIME type sniffing23 res.setHeader('X-Content-Type-Options', 'nosniff');24 25 // Enable XSS protection26 res.setHeader('X-XSS-Protection', '1; mode=block');27 28 // Referrer policy29 res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin');30 31 // Permissions policy32 res.setHeader('Permissions-Policy', 'geolocation=(), microphone=(), camera=()');33 34 next();35}36 37/**38 * Validate Content-Type for POST/PUT requests39 */40function validateContentType(req, res, next) {41 if (['POST', 'PUT', 'PATCH'].includes(req.method)) {42 const contentType = req.get('Content-Type');43 44 if (!contentType) {45 return res.status(400).json({ msg: 'Content-Type header is required' });46 }47 48 // Allow application/json and multipart/form-data49 if (!contentType.includes('application/json') && 50 !contentType.includes('multipart/form-data') &&51 !contentType.includes('application/x-www-form-urlencoded')) {52 return res.status(415).json({ msg: 'Unsupported Media Type' });53 }54 }55 next();56}57 58module.exports = {59 removeServerHeader,60 addSecurityHeaders,61 validateContentType,62};63 