basalt / fastify/src / SecurityHeadersOptions
Interface: SecurityHeadersOptions
Defined in: http/src/security.ts:138
Properties
cacheControl?
> optional cacheControl?: string | false
Defined in: http/src/security.ts:156
Cache-Control value. Defaults to no-store: API responses carry session tokens, API keys and MFA secrets that no browser or intermediary cache may keep. A route that is safe to cache sets its own header (it replaces this one); pass a string to change the default, or false to omit it.
contentSecurityPolicy?
> optional contentSecurityPolicy?: string | false
Defined in: http/src/security.ts:148
Content-Security-Policy value. Defaults to DEFAULT_CSP (a lock-down policy fit for a JSON API); pass a string to use your own, or false to omit the header entirely.
contentTypeOptions?
> optional contentTypeOptions?: boolean
Defined in: http/src/security.ts:140
crossOriginOpenerPolicy?
> optional crossOriginOpenerPolicy?: string | false
Defined in: http/src/security.ts:149
frameOptions?
> optional frameOptions?: false | "DENY" | "SAMEORIGIN"
Defined in: http/src/security.ts:141
hsts?
> optional hsts?: boolean | { includeSubDomains?: boolean; maxAge?: number; preload?: boolean; }
Defined in: http/src/security.ts:139
referrerPolicy?
> optional referrerPolicy?: string | false
Defined in: http/src/security.ts:142