codekingpro/portable-devtools
115k
1##########################################################################2#3# pgAdmin 4 - PostgreSQL Tools4#5# Copyright (C) 2013 - 2024, The pgAdmin Development Team6# This software is released under the PostgreSQL Licence7#8#########################################################################9 10import config11 12 13class SecurityHeaders:14 15 @staticmethod16 def set_response_headers(response):17 """set response security headers"""18 19 params_dict = {20 'CONTENT_SECURITY_POLICY': 'Content-Security-Policy',21 'X_CONTENT_TYPE_OPTIONS': 'X-Content-Type-Options',22 'X_XSS_PROTECTION': 'X-XSS-Protection',23 'WEB_SERVER': 'Server',24 }25 26 # X-Frame-Options for security27 if config.X_FRAME_OPTIONS != "" and \28 config.X_FRAME_OPTIONS.lower() != "deny":29 response.headers["X-Frame-Options"] = config.X_FRAME_OPTIONS30 31 # Strict-Transport-Security32 if config.STRICT_TRANSPORT_SECURITY_ENABLED and \33 config.STRICT_TRANSPORT_SECURITY != "":34 response.headers["Strict-Transport-Security"] = \35 config.STRICT_TRANSPORT_SECURITY36 37 # add other security options38 for key in params_dict:39 if key in config.__dict__ and config.__dict__[key] != "" \40 and config.__dict__[key] is not None:41 response.headers[params_dict[key]] = config.__dict__[key]42 