mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 13:02:49 +08:00
feat(auth): X-Frame-Options + CSP frame-ancestors clickjacking defence
Every response now carries: X-Frame-Options: DENY Content-Security-Policy: frame-ancestors 'none' Prevents the WebUI from being embedded in a third-party iframe. Combined with the existing CSRF Origin-host check, this closes the last meaningful UI-redress surface. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
b6b9aa07bc
commit
a0f290459d
2 files changed
+49
No files matched your search
@@ -58,6 +58,15 @@ export function createWebServer(options: WebServerOptions): WebServer {
|
||||
app.set("trust proxy", true);
|
||||
}
|
||||
|
||||
// Security headers: prevent the WebUI from being embedded in a third-party
|
||||
// iframe (clickjacking defence). CSP frame-ancestors is the modern equivalent
|
||||
// of X-Frame-Options; both are set for compatibility across browsers.
|
||||
app.use((_req, res, next) => {
|
||||
res.setHeader("X-Frame-Options", "DENY");
|
||||
res.setHeader("Content-Security-Policy", "frame-ancestors 'none'");
|
||||
next();
|
||||
});
|
||||
|
||||
app.use(express.json({ limit: "400kb" }));
|
||||
app.use(cookieParser());
|
||||
|
||||
|
||||
Reference in new issue
Block a user