Files
ccn/Services/Website/Sources/Library/Public/Extensions/ConfigKey+Constants.swift
T
javier 6b6389cb0f Security header setup for the Website service (#8)
This PR contains the work done to add a `SecurityHeadersMiddleware` middleware that stamps hardened security-related HTTP headers onto every response.

To provide further details about the work:

* Implemented the `SecurityHeadersMiddleware` middleware, which precomputes headers once from a `Configuration` object and applies them to every response:
  * _Content-Security-Policy_,
  * _X-Content-Type-Options_,
  * _X-Frame-Options_,
  * _Referrer-Policy_,
  * _Permissions-Policy_,
  * _Strict-Transport-Security_ (optional).
* Integrated this middleware into the router (near the top of the chain), reading each value from configuration with hardened defaults.
* The _Strict-Transport-Security_ has no default value — omitted unless explicitly set, so it stays off in plain-HTTP during development and on only behind TLS.
* Added security-header constants keys and values.

Reviewed-on: rock-n-code/loud-amsterdam#8
Co-authored-by: Javier Cicchelli <javier@rock-n-code.com>
Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
2026-06-28 11:35:54 +00:00

53 lines
3.0 KiB
Swift

import Configuration
extension ConfigKey {
/// A namespace for the static files cache configuration keys.
public enum Cache {
/// The configuration key for the max-age, in seconds, applied to text-based static files (CSS, JavaScript, plain text).
public static let maxAgeText: ConfigKey = "cache.maxAge.text"
/// The configuration key for the max-age, in seconds, applied to image static files (ICO, PNG, SVG).
public static let maxAgeImage: ConfigKey = "cache.maxAge.image"
/// The configuration key for the max-age, in seconds, applied to all other static files (e.g. the web manifest).
public static let maxAgeDefault: ConfigKey = "cache.maxAge.default"
}
/// A namespace for the response compression configuration keys.
public enum Compression {
/// The configuration key for the minimum response body size, in bytes, before compression is applied.
public static let minResponseSize: ConfigKey = "compression.minimumResponseSize"
}
/// A namespace for the HTTP server configuration keys.
public enum HTTP {
/// The configuration key for the host the server binds to.
public static let host: ConfigKey = "http.host"
/// The configuration key for the port the server listens on.
public static let port: ConfigKey = "http.port"
/// The configuration key for the server's name.
public static let serverName: ConfigKey = "http.serverName"
}
/// A namespace for the logging configuration keys.
public enum Log {
/// The configuration key for the minimum log level.
public static let level: ConfigKey = "log.level"
}
/// A namespace for the path configuration keys.
public enum Path {
/// The configuration key for the directory the static files are served from.
public static let staticFiles: ConfigKey = "path.staticFiles"
}
/// A namespace for the security headers configuration keys.
public enum Security {
/// The configuration key for the `Content-Security-Policy` header value.
public static let contentSecurityPolicy: ConfigKey = "security.contentSecurityPolicy"
/// The configuration key for the `X-Content-Type-Options` header value.
public static let contentTypeOptions: ConfigKey = "security.contentTypeOptions"
/// The configuration key for the `X-Frame-Options` header value.
public static let frameOptions: ConfigKey = "security.frameOptions"
/// The configuration key for the `Referrer-Policy` header value.
public static let referrerPolicy: ConfigKey = "security.referrerPolicy"
/// The configuration key for the `Permissions-Policy` header value.
public static let permissionsPolicy: ConfigKey = "security.permissionsPolicy"
/// The configuration key for the `Strict-Transport-Security` header value (omitted when unset).
public static let strictTransportSecurity: ConfigKey = "security.strictTransportSecurity"
}
}