extension String { /// A namespace for the persistence's default configuration values and recognized tokens. public enum Database { /// The default persistence driver: in-memory SQLite, which needs no external infrastructure. public static let driver = "inMemory" /// The driver token selecting the MySQL/MariaDB backend. public static let driverMySQL = "mysql" /// The default MySQL/MariaDB host. public static let host = "localhost" /// The default database name. public static let name = "loud" /// The default database username. public static let username = "loud" /// The default TLS posture token. public static let tls = "prefer" /// The TLS token disabling TLS. public static let tlsOff = "off" /// The TLS token requiring TLS. public static let tlsRequire = "require" } /// A namespace for well-known path string constants. public enum Path { /// The directory, relative to the working directory, that the website's static files are served from. public static let staticResources = "Resources/Static" } /// A namespace for the security headers' default configuration values. /// /// `Strict-Transport-Security` is intentionally absent: it is only safe over HTTPS and is /// "sticky" in browsers, so it stays off unless explicitly configured in production. public enum Security { /// The default `Content-Security-Policy`. /// /// Restricts every resource to the site's own origin (`default-src 'self'`), blocks plugins /// (`object-src 'none'`), pins the document base URL (`base-uri 'self'`), and forbids framing /// (`frame-ancestors 'none'`). Both pages link external stylesheets, so no inline-style /// exception is required. public static let contentSecurityPolicy = "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'" /// The default `X-Content-Type-Options` (disables MIME sniffing). public static let contentTypeOptions = "nosniff" /// The default `X-Frame-Options` (forbids framing the page). public static let frameOptions = "DENY" /// The default `Referrer-Policy`. public static let referrerPolicy = "strict-origin-when-cross-origin" /// The default `Permissions-Policy` (denies access to powerful browser features the site does not use). public static let permissionsPolicy = "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()" } /// A namespace for the server string constants. public enum Server { /// The website server's name. public static let name = "LoudWebsite" } }