extension String { /// A namespace for the security headers' default configuration values. /// /// `Strict-Transport-Security` is intentionally absent: it is only safe over HTTPS and is /// "sticky" in browsers, so it stays off unless explicitly configured in production. public enum Security { /// The default `Content-Security-Policy`. /// /// Restricts every resource to the site's own origin (`default-src 'self'`), blocks plugins /// (`object-src 'none'`), pins the document base URL (`base-uri 'self'`), and forbids framing /// (`frame-ancestors 'none'`). No inline-style exception is included, so pages must link /// external stylesheets. public static let contentSecurityPolicy = "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'" /// The default `X-Content-Type-Options` (disables MIME sniffing). public static let contentTypeOptions = "nosniff" /// The default `X-Frame-Options` (forbids framing the page). public static let frameOptions = "DENY" /// The default `Referrer-Policy`. public static let referrerPolicy = "strict-origin-when-cross-origin" /// The default `Permissions-Policy` (denies access to powerful browser features a static site does not use). public static let permissionsPolicy = "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()" } }