helmet-crossdomain
    Overview
    Documentation
    Insights
    Code
    Contributors
    Dependencies
    Alternatives

helmet-crossdomain

Set the X-Permitted-Cross-Domain-Policies header in Express apps

0.5.0  •  Published 3 months ago  •  by helmetjs  •  MIT License

X-Permitted-Cross-Domain-Policies middleware

Build Status

The X-Permitted-Cross-Domain-Policies header tells some web clients (like Adobe Flash or Adobe Acrobat) your domain’s policy for loading cross-domain content. See the description on OWASP for more.

Usage:

const crossdomain = require('helmet-crossdomain')

// Sets X-Permitted-Cross-Domain-Policies: none
app.use(crossdomain())

// You can use any of the following values:
app.use(crossdomain({ permittedPolicies: 'none' }))
app.use(crossdomain({ permittedPolicies: 'master-only' }))
app.use(crossdomain({ permittedPolicies: 'by-content-type' }))
app.use(crossdomain({ permittedPolicies: 'all' }))

The by-ftp-type is not currently supported. Please open an issue or pull request if you desire this feature!

If you don’t expect Adobe products to load data from your site, you get a minor security benefit by adding this header.

How do you feel about the name Devstore for this site?

Popularity

Weekly Downloads
456.0K
Stars
10

Maintenance

Development

Last ver 3 months ago
Created 5 years ago
Last commit 3 months ago
1 month between commits

Technology

Node version: 12.6.0
5.5K unpacked

Compliance

MIT License
OSI Approved
0 vulnerabilities

Contributors

4 contributors
Evan Hahn
Maintainer, 52 commits, 3 merges, 1 PRs
Works at Airtable
Sebastián Zaffarano
1 commits, 1 PRs
Ben James
1 commits, 1 PRs
Works at charisma-ai
dependabot[bot]
1 commits
Adam Baldwin
Maintainer
Works at npm
dependabot
2 PRs

Tags

security
express
connect
crossdomain.xml
x-permitted-cross-domain-policies
flash
Ready for the next level?
Join Devstore's founding team to help us build the ultimate open-source app store, work with the latest technologies, and enjoy great culture, impact and autonomy
© 2019 Devstore, Inc.
Devstore helps developers find and use open-source packages, so they can focus on building amazing things