Files
codeql/javascript/ql/test/query-tests/Security/CWE-693/InsecureHelmetBad.js
2024-05-20 12:05:42 +01:00

18 lines
383 B
JavaScript

const express = require("express");
const helmet = require("helmet");
const app = express();
app.use(helmet({
contentSecurityPolicy: false, // BAD: switch off default CSP
frameguard: false // BAD: switch off default frameguard
}));
app.get("/", (req, res) => {
res.send("Hello, world!");
});
app.listen(3000, () => {
console.log("App is listening on port 3000");
});