Added security scripts support

This commit is contained in:
2026-09-19 22:07:57 +02:00
parent 1186f4f620
commit 9101a5b48e
17 changed files with 404 additions and 42 deletions
+8
View File
@@ -13,6 +13,14 @@ export type BuildSecurityHeadersArgs = {
* domains (scripts, images, fonts, analytics). Keep CSP in your project.
*/
additional?: SecurityHeader[];
/**
* Cross-Origin-Opener-Policy. Default 'same-origin' — isolates the browsing
* context so a malicious page can't hold a window.opener reference (protects
* against XS-Leaks / Spectre-class attacks). Project-independent, so it's a
* default. Use 'same-origin-allow-popups' if you open OAuth/payment popups
* that need window.opener; false to omit.
*/
coop?: 'same-origin' | 'same-origin-allow-popups' | false;
/**
* X-Frame-Options value. 'DENY' (default) blocks all framing; 'SAMEORIGIN'
* allows same-origin framing. Note: CSP frame-ancestors supersedes this in