codekingpro/portable-devtools
114k
1'use strict'
2
3const corsSafeListedMethods = /** @type {const} */ (['GET', 'HEAD', 'POST'])
4const corsSafeListedMethodsSet = new Set(corsSafeListedMethods)
5
6const nullBodyStatus = /** @type {const} */ ([101, 204, 205, 304])
7
8const redirectStatus = /** @type {const} */ ([301, 302, 303, 307, 308])
9const redirectStatusSet = new Set(redirectStatus)
10
11/**
12 * @see https://fetch.spec.whatwg.org/#block-bad-port
13 */
14const badPorts = /** @type {const} */ ([
15 '1', '7', '9', '11', '13', '15', '17', '19', '20', '21', '22', '23', '25', '37', '42', '43', '53', '69', '77', '79',
16 '87', '95', '101', '102', '103', '104', '109', '110', '111', '113', '115', '117', '119', '123', '135', '137',
17 '139', '143', '161', '179', '389', '427', '465', '512', '513', '514', '515', '526', '530', '531', '532',
18 '540', '548', '554', '556', '563', '587', '601', '636', '989', '990', '993', '995', '1719', '1720', '1723',
19 '2049', '3659', '4045', '4190', '5060', '5061', '6000', '6566', '6665', '6666', '6667', '6668', '6669', '6679',
20 '6697', '10080'
21])
22const badPortsSet = new Set(badPorts)
23
24/**
25 * @see https://w3c.github.io/webappsec-referrer-policy/#referrer-policies
26 */
27const referrerPolicy = /** @type {const} */ ([
28 '',
29 'no-referrer',
30 'no-referrer-when-downgrade',
31 'same-origin',
32 'origin',
33 'strict-origin',
34 'origin-when-cross-origin',
35 'strict-origin-when-cross-origin',
36 'unsafe-url'
37])
38const referrerPolicySet = new Set(referrerPolicy)
39
40const requestRedirect = /** @type {const} */ (['follow', 'manual', 'error'])
41
42const safeMethods = /** @type {const} */ (['GET', 'HEAD', 'OPTIONS', 'TRACE'])
43const safeMethodsSet = new Set(safeMethods)
44
45const requestMode = /** @type {const} */ (['navigate', 'same-origin', 'no-cors', 'cors'])
46
47const requestCredentials = /** @type {const} */ (['omit', 'same-origin', 'include'])
48
49const requestCache = /** @type {const} */ ([
50 'default',
51 'no-store',
52 'reload',
53 'no-cache',
54 'force-cache',
55 'only-if-cached'
56])
57
58/**
59 * @see https://fetch.spec.whatwg.org/#request-body-header-name
60 */
61const requestBodyHeader = /** @type {const} */ ([
62 'content-encoding',
63 'content-language',
64 'content-location',
65 'content-type',
66 // See https://github.com/nodejs/undici/issues/2021
67 // 'Content-Length' is a forbidden header name, which is typically
68 // removed in the Headers implementation. However, undici doesn't
69 // filter out headers, so we add it here.
70 'content-length'
71])
72
73/**
74 * @see https://fetch.spec.whatwg.org/#enumdef-requestduplex
75 */
76const requestDuplex = /** @type {const} */ ([
77 'half'
78])
79
80/**
81 * @see http://fetch.spec.whatwg.org/#forbidden-method
82 */
83const forbiddenMethods = /** @type {const} */ (['CONNECT', 'TRACE', 'TRACK'])
84const forbiddenMethodsSet = new Set(forbiddenMethods)
85
86const subresource = /** @type {const} */ ([
87 'audio',
88 'audioworklet',
89 'font',
90 'image',
91 'manifest',
92 'paintworklet',
93 'script',
94 'style',
95 'track',
96 'video',
97 'xslt',
98 ''
99])
100const subresourceSet = new Set(subresource)
101
102module.exports = {
103 subresource,
104 forbiddenMethods,
105 requestBodyHeader,
106 referrerPolicy,
107 requestRedirect,
108 requestMode,
109 requestCredentials,
110 requestCache,
111 redirectStatus,
112 corsSafeListedMethods,
113 nullBodyStatus,
114 safeMethods,
115 badPorts,
116 requestDuplex,
117 subresourceSet,
118 badPortsSet,
119 redirectStatusSet,
120 corsSafeListedMethodsSet,
121 safeMethodsSet,
122 forbiddenMethodsSet,
123 referrerPolicySet
124}
125 