This PR contains the work done to add a `SecurityHeadersMiddleware` middleware that stamps hardened security-related HTTP headers onto every response. To provide further details about the work: * Implemented the `SecurityHeadersMiddleware` middleware, which precomputes headers once from a `Configuration` object and applies them to every response: * _Content-Security-Policy_, * _X-Content-Type-Options_, * _X-Frame-Options_, * _Referrer-Policy_, * _Permissions-Policy_, * _Strict-Transport-Security_ (optional). * Integrated this middleware into the router (near the top of the chain), reading each value from configuration with hardened defaults. * The _Strict-Transport-Security_ has no default value — omitted unless explicitly set, so it stays off in plain-HTTP during development and on only behind TLS. * Added security-header constants keys and values. Reviewed-on: rock-n-code/loud-amsterdam#8 Co-authored-by: Javier Cicchelli <javier@rock-n-code.com> Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
53 lines
3.3 KiB
Swift
53 lines
3.3 KiB
Swift
import Configuration
|
|
|
|
extension AbsoluteConfigKey {
|
|
/// A namespace for the static files cache configuration keys, as absolute keys.
|
|
public enum Cache {
|
|
/// The absolute configuration key for the max-age, in seconds, applied to text-based static files.
|
|
public static let maxAgeText: AbsoluteConfigKey = .init(.Cache.maxAgeText)
|
|
/// The absolute configuration key for the max-age, in seconds, applied to image static files.
|
|
public static let maxAgeImage: AbsoluteConfigKey = .init(.Cache.maxAgeImage)
|
|
/// The absolute configuration key for the max-age, in seconds, applied to all other static files.
|
|
public static let maxAgeDefault: AbsoluteConfigKey = .init(.Cache.maxAgeDefault)
|
|
}
|
|
/// A namespace for the response compression configuration keys, as absolute keys.
|
|
public enum Compression {
|
|
/// The absolute configuration key for the minimum response body size, in bytes, before compression is applied.
|
|
public static let minResponseSize: AbsoluteConfigKey = .init(.Compression.minResponseSize)
|
|
}
|
|
/// A namespace for the HTTP server configuration keys, as absolute keys.
|
|
public enum HTTP {
|
|
/// The absolute configuration key for the host the server binds to.
|
|
public static let host: AbsoluteConfigKey = .init(.HTTP.host)
|
|
/// The absolute configuration key for the port the server listens on.
|
|
public static let port: AbsoluteConfigKey = .init(.HTTP.port)
|
|
/// The absolute configuration key for the server's name.
|
|
public static let serverName: AbsoluteConfigKey = .init(.HTTP.serverName)
|
|
}
|
|
/// A namespace for the logging configuration keys, as absolute keys.
|
|
public enum Log {
|
|
/// The absolute configuration key for the minimum log level.
|
|
public static let level: AbsoluteConfigKey = .init(.Log.level)
|
|
}
|
|
/// A namespace for the path configuration keys, as absolute keys.
|
|
public enum Path {
|
|
/// The absolute configuration key for the directory the static files are served from.
|
|
public static let staticFiles: AbsoluteConfigKey = .init(.Path.staticFiles)
|
|
}
|
|
/// A namespace for the security headers configuration keys, as absolute keys.
|
|
public enum Security {
|
|
/// The absolute configuration key for the `Content-Security-Policy` header value.
|
|
public static let contentSecurityPolicy: AbsoluteConfigKey = .init(.Security.contentSecurityPolicy)
|
|
/// The absolute configuration key for the `X-Content-Type-Options` header value.
|
|
public static let contentTypeOptions: AbsoluteConfigKey = .init(.Security.contentTypeOptions)
|
|
/// The absolute configuration key for the `X-Frame-Options` header value.
|
|
public static let frameOptions: AbsoluteConfigKey = .init(.Security.frameOptions)
|
|
/// The absolute configuration key for the `Referrer-Policy` header value.
|
|
public static let referrerPolicy: AbsoluteConfigKey = .init(.Security.referrerPolicy)
|
|
/// The absolute configuration key for the `Permissions-Policy` header value.
|
|
public static let permissionsPolicy: AbsoluteConfigKey = .init(.Security.permissionsPolicy)
|
|
/// The absolute configuration key for the `Strict-Transport-Security` header value.
|
|
public static let strictTransportSecurity: AbsoluteConfigKey = .init(.Security.strictTransportSecurity)
|
|
}
|
|
}
|