Module: SecureHeaders
- Defined in:
- lib/secure_headers.rb,
lib/secure_headers/header.rb,
lib/secure_headers/padrino.rb,
lib/secure_headers/railtie.rb,
lib/secure_headers/version.rb,
lib/secure_headers/hash_helper.rb,
lib/secure_headers/view_helper.rb,
lib/secure_headers/controller_extension.rb,
lib/secure_headers/headers/public_key_pins.rb,
lib/secure_headers/headers/x_frame_options.rb,
lib/secure_headers/headers/x_xss_protection.rb,
lib/secure_headers/headers/x_download_options.rb,
lib/secure_headers/headers/x_content_type_options.rb,
lib/secure_headers/headers/content_security_policy.rb,
lib/secure_headers/headers/strict_transport_security.rb,
lib/secure_headers/headers/x_permitted_cross_domain_policies.rb,
lib/secure_headers/headers/content_security_policy/script_hash_middleware.rb
Defined Under Namespace
Modules: Configuration, ControllerExtension, HashHelper, Padrino, ViewHelpers
Classes: ContentSecurityPolicy, ContentSecurityPolicyBuildError, Header, PublicKeyPins, PublicKeyPinsBuildError, Railtie, STSBuildError, StrictTransportSecurity, UnexpectedHashedScriptException, XContentTypeOptions, XContentTypeOptionsBuildError, XDOBuildError, XDownloadOptions, XFOBuildError, XFrameOptions, XPCDPBuildError, XPermittedCrossDomainPolicies, XXssProtection, XXssProtectionBuildError
Constant Summary
collapse
- SCRIPT_HASH_CONFIG_FILE =
'config/script_hashes.yml'
- HASHES_ENV_KEY =
'secure_headers.script_hashes'
[
::ContentSecurityPolicy,
::StrictTransportSecurity,
::PublicKeyPins,
::XContentTypeOptions,
::XDownloadOptions,
::XFrameOptions,
::XPermittedCrossDomainPolicies,
::XXssProtection
]
- ALL_FILTER_METHODS =
[
:prep_script_hash,
:set_hsts_header,
:set_hpkp_header,
:set_x_frame_options_header,
:set_csp_header,
:set_x_xss_protection_header,
:set_x_content_type_options_header,
:set_x_download_options_header,
:set_x_permitted_cross_domain_policies_header
]
- VERSION =
"2.5.3"
Class Method Summary
collapse
Class Method Details
.append_features(base) ⇒ Object
65
66
67
|
# File 'lib/secure_headers.rb', line 65
def append_features(base)
base.send(:include, ControllerExtension)
end
|
87
88
89
90
|
# File 'lib/secure_headers.rb', line 87
def (klass, options)
return if options == false
klass.new(options)
end
|
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
|
# File 'lib/secure_headers.rb', line 69
def (options = nil)
.inject({}) do |memo, klass|
config = if options.is_a?(Hash) && !options[klass::Constants::CONFIG_KEY].nil?
options[klass::Constants::CONFIG_KEY]
else
::::Configuration.send(klass::Constants::CONFIG_KEY)
end
unless klass == ::PublicKeyPins && !config.is_a?(Hash)
= (klass, config)
memo[.name] = .value if
end
memo
end
end
|