Skip to content

Commit b680464

Browse files
committed
set max-age for hsts header
1 parent 3d98423 commit b680464

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

server/server.js

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,8 +54,9 @@ app.use(helmet.contentSecurityPolicy({
5454
// Set secure headers
5555
if (process.env.PRODUCTION === true || process.env.PRODUCTION == "true") {
5656
console.log("Running in production - setting headers")
57-
app.use(helmet.hsts());
58-
// app.use(helmet.contentSecurityPolicy()); Need more testing
57+
app.use(helmet.hsts({
58+
maxAge: 31536000,
59+
}));
5960
app.use(helmet.noSniff());
6061
app.use(helmet.frameguard());
6162
}

0 commit comments

Comments
 (0)