Blockade ⚓️ is a lightweight package that adds optional security headers and cookie attributes for Node.js web frameworks.
Security HTTP headers and cookie attributes help enhance the security of your web application by enabling built-in browser security mechanisms.
AdonisJs, Express, Fastify, hapi, Koa, Meteor, Nest, Polka, restify, Sails, Total.js
$ npm i blockadeAfter installing Blockade:
constblockade=require("blockade");constsecureHeaders=newblockade.SecureHeaders();constsecureCookie=newblockade.SecureCookie();secureHeaders.framework(response);
Default HTTP response headers:
Strict-Transport-Security: max-age=63072000; includeSubdomainsX-Frame-Options: SAMEORIGINX-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffReferrer-Policy: no-referrer, strict-origin-when-cross-originCache-control: no-cache, no-store, must-revalidate, max-age=0Pragma: no-cacheExpires: 0secureCookie.framework(response,"foo","bar");Default Set-Cookie HTTP response header:
Set-Cookie: foo=bar; Path=/; secure; HttpOnly; SameSite=laxPlease see the full set of documentation at https://blockadejs.readthedocs.io