Team Ai
Apppublic

sanket3280/code-execution

sourceHugging Faceupdated 11mo agoView on Hugging Face
0likes
security.js63 linesDownload Raw Back to middleware
1/**2 * Security Middleware3 * Additional security measures beyond helmet4 */5 6/**7 * Remove sensitive headers from responses8 */9function removeServerHeader(_req, res, next) {10  res.removeHeader('X-Powered-By');11  res.removeHeader('Server');12  next();13}14 15/**16 * Add custom security headers17 */18function addSecurityHeaders(_req, res, next) {19  // Prevent clickjacking20  res.setHeader('X-Frame-Options', 'DENY');21  22  // Prevent MIME type sniffing23  res.setHeader('X-Content-Type-Options', 'nosniff');24  25  // Enable XSS protection26  res.setHeader('X-XSS-Protection', '1; mode=block');27  28  // Referrer policy29  res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin');30  31  // Permissions policy32  res.setHeader('Permissions-Policy', 'geolocation=(), microphone=(), camera=()');33  34  next();35}36 37/**38 * Validate Content-Type for POST/PUT requests39 */40function validateContentType(req, res, next) {41  if (['POST', 'PUT', 'PATCH'].includes(req.method)) {42    const contentType = req.get('Content-Type');43    44    if (!contentType) {45      return res.status(400).json({ msg: 'Content-Type header is required' });46    }47    48    // Allow application/json and multipart/form-data49    if (!contentType.includes('application/json') && 50        !contentType.includes('multipart/form-data') &&51        !contentType.includes('application/x-www-form-urlencoded')) {52      return res.status(415).json({ msg: 'Unsupported Media Type' });53    }54  }55  next();56}57 58module.exports = {59  removeServerHeader,60  addSecurityHeaders,61  validateContentType,62};63