2026-08-19 22:55:00 +02:00
|
|
|
extension String {
|
|
|
|
|
/// A namespace for the security headers' default configuration values.
|
|
|
|
|
///
|
|
|
|
|
/// `Strict-Transport-Security` is intentionally absent: it is only safe over HTTPS and is "sticky" in browsers, so it stays off unless explicitly
|
|
|
|
|
/// configured in production.
|
|
|
|
|
public enum Security {
|
|
|
|
|
/// The default `Content-Security-Policy`.
|
|
|
|
|
///
|
|
|
|
|
/// Restricts every resource to the site's own origin (`default-src 'self'`), blocks plugins (`object-src 'none'`), pins the document
|
2026-09-20 12:45:58 +02:00
|
|
|
/// base URL (`base-uri 'self'`), holds form submissions to the origin (`form-action 'self'`), and forbids framing
|
|
|
|
|
/// (`frame-ancestors 'none'`). No inline-style exception is included, so pages must link external stylesheets.
|
|
|
|
|
///
|
|
|
|
|
/// `form-action` is named outright because it inherits from nothing: `default-src` does not cover it, however tight.
|
|
|
|
|
public static let contentSecurityPolicy = "default-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'"
|
2026-08-19 22:55:00 +02:00
|
|
|
/// The default `X-Content-Type-Options` (disables MIME sniffing).
|
|
|
|
|
public static let contentTypeOptions = "nosniff"
|
|
|
|
|
/// The default `X-Frame-Options` (forbids framing the page).
|
|
|
|
|
public static let frameOptions = "DENY"
|
|
|
|
|
/// The default `Referrer-Policy`.
|
|
|
|
|
public static let referrerPolicy = "strict-origin-when-cross-origin"
|
|
|
|
|
/// The default `Permissions-Policy` (denies access to powerful browser features a static site does not use).
|
|
|
|
|
public static let permissionsPolicy = "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()"
|
|
|
|
|
}
|
|
|
|
|
}
|