@@ -19,6 +19,15 @@ test('it works with the default helmet call', t => {
19
19
// contentSecurityPolicy
20
20
. expect ( 'Content-Security-Policy' , 'default-src \'self\';base-uri \'self\';font-src \'self\' https: data:;form-action \'self\';frame-ancestors \'self\';img-src \'self\' data:;object-src \'none\';script-src \'self\';script-src-attr \'none\';style-src \'self\' https: \'unsafe-inline\';upgrade-insecure-requests' )
21
21
22
+ // crossOriginEmbedderPolicy
23
+ . expect ( 'Cross-Origin-Embedder-Policy' , 'require-corp' )
24
+
25
+ // crossOriginOpenerPolicy
26
+ . expect ( 'Cross-Origin-Opener-Policy' , 'same-origin' )
27
+
28
+ // crossOriginResourcePolicy
29
+ . expect ( 'Cross-Origin-Resource-Policy' , 'same-origin' )
30
+
22
31
// dnsPrefetchControl
23
32
. expect ( 'X-DNS-Prefetch-Control' , 'off' )
24
33
@@ -59,6 +68,9 @@ test('it sets individual headers properly', t => {
59
68
} )
60
69
) ;
61
70
app . use ( helmet . contentSecurityPolicy ( ) ) ;
71
+ app . use ( helmet . crossOriginEmbedderPolicy ( ) ) ;
72
+ app . use ( helmet . crossOriginOpenerPolicy ( ) ) ;
73
+ app . use ( helmet . crossOriginResourcePolicy ( ) ) ;
62
74
app . use (
63
75
helmet . dnsPrefetchControl ( {
64
76
allow : false ,
@@ -82,6 +94,15 @@ test('it sets individual headers properly', t => {
82
94
// contentSecurityPolicy
83
95
. expect ( 'Content-Security-Policy' , 'default-src \'self\';base-uri \'self\';font-src \'self\' https: data:;form-action \'self\';frame-ancestors \'self\';img-src \'self\' data:;object-src \'none\';script-src \'self\';script-src-attr \'none\';style-src \'self\' https: \'unsafe-inline\';upgrade-insecure-requests' )
84
96
97
+ // crossOriginEmbedderPolicy
98
+ . expect ( 'Cross-Origin-Embedder-Policy' , 'require-corp' )
99
+
100
+ // crossOriginOpenerPolicy
101
+ . expect ( 'Cross-Origin-Opener-Policy' , 'same-origin' )
102
+
103
+ // crossOriginResourcePolicy
104
+ . expect ( 'Cross-Origin-Resource-Policy' , 'same-origin' )
105
+
85
106
// dnsPrefetchControl
86
107
. expect ( 'X-DNS-Prefetch-Control' , 'off' )
87
108
0 commit comments