Skip to content

basalt / fastify/src / SecurityHeadersOptions

Interface: SecurityHeadersOptions ​

Defined in: http/src/security.ts:138

Properties ​

cacheControl? ​

> optional cacheControl?: string | false

Defined in: http/src/security.ts:156

Cache-Control value. Defaults to no-store: API responses carry session tokens, API keys and MFA secrets that no browser or intermediary cache may keep. A route that is safe to cache sets its own header (it replaces this one); pass a string to change the default, or false to omit it.


contentSecurityPolicy? ​

> optional contentSecurityPolicy?: string | false

Defined in: http/src/security.ts:148

Content-Security-Policy value. Defaults to DEFAULT_CSP (a lock-down policy fit for a JSON API); pass a string to use your own, or false to omit the header entirely.


contentTypeOptions? ​

> optional contentTypeOptions?: boolean

Defined in: http/src/security.ts:140


crossOriginOpenerPolicy? ​

> optional crossOriginOpenerPolicy?: string | false

Defined in: http/src/security.ts:149


frameOptions? ​

> optional frameOptions?: false | "DENY" | "SAMEORIGIN"

Defined in: http/src/security.ts:141


hsts? ​

> optional hsts?: boolean | { includeSubDomains?: boolean; maxAge?: number; preload?: boolean; }

Defined in: http/src/security.ts:139


referrerPolicy? ​

> optional referrerPolicy?: string | false

Defined in: http/src/security.ts:142

Released under the MIT License.