security

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 6 Imported by: 0

README

Security Headers Middleware

What it does

Adds common defensive HTTP headers such as content type protection, frame options, referrer policy, HSTS, and CSP-related headers depending on config.

How to implement

package main

import (
	"github.com/oarkflow/fh"
	"github.com/oarkflow/fh/mw/security"
)

func main() {
	app := fh.New()
	app.Use(security.New(security.Config{}))

	app.Get("/", func(c fh.Ctx) error {
		return c.Status(fh.StatusOK).SendString("ok")
	})
}

Impact

Improves browser security with very low overhead.

Ordering guidance

Run late enough to apply headers to normal responses, but before response is sent.

Production considerations

Tune CSP carefully; start with report-only where needed. Enable HSTS only when HTTPS is permanent for the domain.

Documentation

Index

Constants

View Source
const CSPNonceLocalKey = "csp_nonce"

Variables

This section is empty.

Functions

func New

func New(config ...Config) fh.HandlerFunc

Types

type Config

type Config struct {
	ContentSecurityPolicy           string
	ContentSecurityPolicyReportOnly string
	CSPNonce                        bool
	CSPNonceDirectives              []string
	HSTSMaxAge                      int
	HSTSIncludeSubDomains           bool
	HSTSPreload                     bool
	FrameDeny                       bool
	ContentTypeNosniff              bool
	XSSProtection                   string
	CrossOriginOpenerPolicy         string
	CrossOriginResourcePolicy       string
	CrossOriginEmbedderPolicy       string
	ReferrerPolicy                  string
	PermissionsPolicy               string
	// Disable* fields make it possible to turn off an individual default while
	// retaining the rest of the middleware's secure baseline.
	DisableFrameDeny          bool
	DisableContentTypeNosniff bool
	DisableHSTS               bool
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL