aboutsummaryrefslogtreecommitdiff
path: root/middleware/common_headers.go
diff options
context:
space:
mode:
authorGravatar Frédéric Guillot <fred@miniflux.net> 2018-10-07 18:42:43 -0700
committerGravatar Frédéric Guillot <fred@miniflux.net> 2018-10-08 15:31:58 -0700
commit1f58b37a5e86603b16e137031c36f37580e9d410 (patch)
tree337a7299e91fe7640b64489357dfe7c0f00e2313 /middleware/common_headers.go
parentddfe969d6cbc8d23326cb9a3ca9a265d4e9d3e45 (diff)
downloadv2-1f58b37a5e86603b16e137031c36f37580e9d410.tar.gz
v2-1f58b37a5e86603b16e137031c36f37580e9d410.tar.zst
v2-1f58b37a5e86603b16e137031c36f37580e9d410.zip
Refactor HTTP response builder
Diffstat (limited to 'middleware/common_headers.go')
-rw-r--r--middleware/common_headers.go25
1 files changed, 0 insertions, 25 deletions
diff --git a/middleware/common_headers.go b/middleware/common_headers.go
deleted file mode 100644
index a60969f7..00000000
--- a/middleware/common_headers.go
+++ /dev/null
@@ -1,25 +0,0 @@
-// Copyright 2018 Frédéric Guillot. All rights reserved.
-// Use of this source code is governed by the Apache 2.0
-// license that can be found in the LICENSE file.
-
-package middleware // import "miniflux.app/middleware"
-
-import (
- "net/http"
-)
-
-// CommonHeaders sends common HTTP headers.
-func (m *Middleware) CommonHeaders(next http.Handler) http.Handler {
- return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- w.Header().Set("X-XSS-Protection", "1; mode=block")
- w.Header().Set("X-Content-Type-Options", "nosniff")
- w.Header().Set("X-Frame-Options", "DENY")
- w.Header().Set("Content-Security-Policy", "default-src 'self'; img-src *; media-src *; frame-src *; child-src *")
-
- if m.cfg.IsHTTPS && m.cfg.HasHSTS() {
- w.Header().Set("Strict-Transport-Security", "max-age=31536000")
- }
-
- next.ServeHTTP(w, r)
- })
-}