{"_id":"next-secure-headers","_rev":"5-276d89f11fec514f4ae84fba81b29a38","name":"next-secure-headers","dist-tags":{"latest":"2.2.0"},"versions":{"1.0.0":{"name":"next-secure-headers","version":"1.0.0","description":"Sets secure response headers for Next.js.","keywords":["Next.js","headers","security","csp"],"homepage":"https://github.com/jagaapple/next-secure-headers","bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","author":{"name":"Jaga Apple"},"contributors":[],"main":"lib/index.js","bin":"","man":"","repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"scripts":{"prebuild":"rm -rf ./lib","build":"tsc","lint":"eslint ./src/**/*.ts","fix":"eslint --fix ./src/**/*.ts","prepublishOnly":"npm run build","test":"jest --coverage","coverage":"codecov","clean":"rm -rf ./lib ./coverage"},"config":{},"dependencies":{},"devDependencies":{"@types/jest":"^24.0.23","@types/jest-plugin-context":"^2.9.2","@types/node":"^12.12.14","@types/react":"^16.9.13","@typescript-eslint/eslint-plugin":"^2.7.0","@typescript-eslint/parser":"^2.7.0","codecov":"^3.6.1","eslint":"^6.6.0","eslint-config-prettier":"^6.6.0","eslint-plugin-import":"^2.18.2","eslint-plugin-prettier":"^3.1.1","jest":"^24.9.0","jest-plugin-context":"^2.9.0","prettier":"^1.19.1","react":"^16.12.0","ts-jest":"^24.1.0","typescript":"^3.7.2"},"peerDependencies":{},"engines":{"node":">=10.0.0"},"engineStrict":false,"preferGlobal":false,"private":false,"gitHead":"1c28446546e20c42f0892fb5e8818705bea9ee5f","_id":"next-secure-headers@1.0.0","_nodeVersion":"10.15.3","_npmVersion":"6.11.3","dist":{"integrity":"sha512-4fIf0OHLFbyhMikdFcurIPS5yIFBU0OvOrP0F5hl0FV+B7f04+RoyQktneG0efytTMnJdBNf2hwVP9y6iz7C6Q==","shasum":"37b7af533a885220a6d675fe4061987be65318d1","tarball":"https://registry.npmjs.org/next-secure-headers/-/next-secure-headers-1.0.0.tgz","fileCount":35,"unpackedSize":52814,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd6CmGCRA9TVsSAnZWagAA8yAP/3EBErLGgSjVgcXzycOW\nSCyuooLLBJEgG6lsaJNdfrErpuBuv2IVMdq+aeisvE10+K7nyevJDnEZz3F/\nqpagVO/e7g/0hqh/IV621UDqgAZeQN4gfy33hNObDb88VaceyhcVoKKutpkL\nPnA93y6d5J4B73Z70dZ76ORrxb7Ovy45Oz8LBUX1qk2cd4RJ5JTjQZ+gJLK2\nuYYZO6Kk2RSy6ZcHX8mzX4lfO9mV2zbmJC+JGSMNme/Ca0vef+lvp4Qxkpjg\nI38Fo6X0zNzCHjnhL9wecTOfV+Ud5Rxga3FIgNwwTEWM/7WUVrfna19lUGHp\ni8ysyEXsqt2dXHmvA7GzEU3C7cWOQO7IBNd2ToFAMEXDzJuVofokg97knJD+\nnTRCt3OCp30xeWwQzIIJ6liCEraXOGuBqWS5IUwoYtnKUNQiVn0oHuHnvpP8\nQfCuk8Ea8iWI2tb7tA2t+GcsUdvKzjPHy0FvIUsppK5+t0mDi7ue94GpYqYS\na+xfuifl7ZUn9gZZRxGSHJyG//U4cFCiC7BQ2UpxhxKvTtCMuAM5T0iCKt+J\nahiY1eu6rVg+nhUk6yoAZUxHzyDg44eQe1U+WE0a7NEQrsmeuXlT5WWlUun8\n+/b1mRCdSYgBxmNlB9S9ZbJneb4eBEk4ej6EbLQ6fPRXuXMuDrbPjmw1NbJ9\nngsX\r\n=d3Z7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDmJeb8yWNX5BhZXV44mx52Fvvp/jkh9OLvzxXKRmdurQIhAKFst1xZxRBqBBorOznQOAKPmrLYc9co+AGHEM5R6SU+"}]},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"_npmUser":{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-secure-headers_1.0.0_1575496070419_0.19458454823878557"},"_hasShrinkwrap":false},"1.0.1":{"name":"next-secure-headers","version":"1.0.1","description":"Sets secure response headers for Next.js.","keywords":["Next.js","headers","security","csp"],"homepage":"https://github.com/jagaapple/next-secure-headers","bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","author":{"name":"Jaga Apple"},"contributors":[],"main":"lib/index.js","bin":"","man":"","repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"scripts":{"prebuild":"rm -rf ./lib","build":"tsc","lint":"eslint ./src/**/*.ts","fix":"eslint --fix ./src/**/*.ts","prepublishOnly":"npm run build","test":"jest --coverage","coverage":"codecov","clean":"rm -rf ./lib ./coverage"},"config":{},"dependencies":{},"devDependencies":{"@types/jest":"^24.0.23","@types/jest-plugin-context":"^2.9.2","@types/node":"^12.12.14","@types/react":"^16.9.13","@typescript-eslint/eslint-plugin":"^2.7.0","@typescript-eslint/parser":"^2.7.0","codecov":"^3.6.1","eslint":"^6.6.0","eslint-config-prettier":"^6.6.0","eslint-plugin-import":"^2.18.2","eslint-plugin-prettier":"^3.1.1","jest":"^24.9.0","jest-plugin-context":"^2.9.0","prettier":"^1.19.1","react":"^16.12.0","ts-jest":"^24.1.0","typescript":"^3.7.2"},"peerDependencies":{},"engines":{"node":">=10.0.0"},"engineStrict":false,"preferGlobal":false,"private":false,"gitHead":"7120dd99ed4e77ff7a1c9d7dd1ba7c5063b2a9f4","_id":"next-secure-headers@1.0.1","_nodeVersion":"10.15.3","_npmVersion":"6.11.3","dist":{"integrity":"sha512-pFlEYtS4YiO2cP6c/0IL4v5KU90OhdVI2ux7tUobT9RZpdx17CQQC1gZOHlw6N6jFLOlVe5REVfJ633FEtdDSQ==","shasum":"924d1766f860c30034fba223a4f8d804554f8ea4","tarball":"https://registry.npmjs.org/next-secure-headers/-/next-secure-headers-1.0.1.tgz","fileCount":35,"unpackedSize":53115,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJd88pZCRA9TVsSAnZWagAAgPYP/AoACw32Xld0SFnZbybu\n5LOEKPfvdsOv64JdelUHoBYE/bK33zpjmLQAbcDIW9gWEOMoVnK+oPFwpcvi\nrXypZqnlslDVBUnRg1mJYEtDJxiHdq+9uHsfP0ztYmkn6RkAOIKchjahzJGK\nS8/wqQaO6PDiQgUseonwrzRfhzVdGbsejgviCkCtKi5F8xQmsQ+LHldWypXT\nzomX1G5CGoO7/AvNZc9mFlq/FB/05EvF/5AtHAX3ADgDG974BJc00PmidMxy\n6sZSx/nbSRGBrgruT7p1ApLGVDSwYSdhQdG8TmepF9uVoGcO4bUJtorgr9Or\nf8expLs4uIUWnr7vAcvbturpLV8jFEf81Sp8mq/BdTUasK0T7Ylh5axHfMxa\n3J7p9pmuMTwBypb4LOPyYvj4xsK/MbC7y1OpLy6VDLM3fMfD8ExJ0BM7xbbn\n1Lx5KEmsqyONMaeI4Z3cfhJXvc+CyIERc05SJWyIyzrWN4k0AqWUjlslY3ra\nI66gy/lV/6gw6ft5UShVxvu0/H6BfY9JvJJLaG89Y9Tnzot5hGiM/ZsXVFPk\nrzoHgzgvhj7IilCwmKFQavViM6u9tU3A/HxCf9gjZLcry1oiVSoLkIURFVcI\n4qOKesxeyN8fqd3ZSIiyJWxK/B3oIyrHtsN7eSGxFlCBo31hBYtfmUpdgEd1\naV6M\r\n=JXPf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHcoTItkmMkcM/grosbtl0HcGqjCyYC7AvRhJpUCVorSAiA+gh2CyxNXiILv8kEOgn1NtGNKOMEwdZ5y+xcKZdLUQg=="}]},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"_npmUser":{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-secure-headers_1.0.1_1576258136541_0.4924301214854683"},"_hasShrinkwrap":false},"2.0.0":{"name":"next-secure-headers","version":"2.0.0","description":"Sets secure response headers for Next.js.","keywords":["Next.js","headers","security","csp"],"homepage":"https://github.com/jagaapple/next-secure-headers","bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","author":{"name":"Jaga Apple"},"contributors":[],"main":"lib/index.js","man":"","repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"scripts":{"prebuild":"rm -rf ./lib","build":"tsc","lint":"eslint ./src/**/*.ts","fix":"eslint --fix ./src/**/*.ts","prepublishOnly":"npm run build","test":"jest --coverage","coverage":"codecov","clean":"rm -rf ./lib ./coverage"},"config":{},"dependencies":{},"devDependencies":{"@types/jest":"^26.0.9","@types/jest-plugin-context":"^2.9.3","@types/node":"^14.0.27","@types/react":"^16.9.44","@typescript-eslint/eslint-plugin":"^3.8.0","@typescript-eslint/parser":"^3.8.0","codecov":"^3.7.2","eslint":"^7.6.0","eslint-config-prettier":"^6.11.0","eslint-plugin-import":"^2.22.0","eslint-plugin-prettier":"^3.1.4","jest":"^26.2.2","jest-plugin-context":"^2.9.0","prettier":"^2.0.5","react":"^16.13.1","ts-jest":"^26.1.4","typescript":"^3.9.7"},"peerDependencies":{},"engines":{"node":">=10.0.0"},"engineStrict":false,"preferGlobal":false,"private":false,"gitHead":"2921f838a8a8984a79b39b1f7689d5fa4880f3f6","_id":"next-secure-headers@2.0.0","_nodeVersion":"10.15.3","_npmVersion":"6.14.5","dist":{"integrity":"sha512-I/erHyPqhYNpmHTzKqVFm1UUq63kTrhIjpPsUEZSmO43yXsNExxb+e6BddzQk2OfUmTsMNo1xRI/7Lythb0A+g==","shasum":"4e4faf3e85dfb11fde71aa5810846608aec6872d","tarball":"https://registry.npmjs.org/next-secure-headers/-/next-secure-headers-2.0.0.tgz","fileCount":35,"unpackedSize":67373,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfLnOiCRA9TVsSAnZWagAAs1YP/iqcD1qrLoJaobjv2ZUp\nbhWzKMmlaBgczA1a3mZI9182T1+h8Jn8V7vLAHC89JZmdvmC7ed36wSy7MBa\nJyP16Ge3wTFkecjKLrYr/iw26D7ISEz4vbgkF6HJfkzaPhxMaPY6tbLKfQ5n\nRE6TXnEC5qxvhucfehp3LvkBUC28h6sYpCYX+Z8r9ILKa+tJUWPKfqpYID0b\nWqAJpnZ22N3qwF+CZIwtNu6W85JwFvjBjScoZiQwulfH8mWm4xxI80ArK+XB\n2vbk904tclJPKBwfwCBXnmRg10nAqxrqmlHy1lWBXbZt2CTJaTTQrJpCWP7P\nsO9wG/51P9YZDSrH581URZbLQBXXCDjpayi/GiqCtOnRECUJXD5LI11JLINK\nXPkIkoe0OxG/tZwxhfr4wqZm8Qqd+BVraoEB8tbWpEUOSTMR7sFvhOVCwz9a\nSFHN7kyij9pxcZQRoMEqLmlAda3ZRgmaqZpuq+EdulvqWi8KxrHFAgFXF/07\nNg0PVLxWOhuyIgsp/eZZXZaiYwTEVnrbP3P8KqvQNc/FO15wVxe1Ac4XPL8c\nBwHr6A2nM9vRzN47PTqlot4fSewzBk0xgbp9VZGXfTBSZY6vsZYllgC6BOIz\ncJHyXJ2DU1iPI8vBx3inirbqKDA0gXvXHGbJ608UmlonH8Up3xyeyG1Bgcxn\n4cDm\r\n=hw9Q\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGDFE4i7sK95ljEgmbkfXyYeLtJ7Q7mUUFsBFCAebZrHAiEAify4+wVHOq78ykHcJGJvz/bvKjDUMcbDcqmz0C438zs="}]},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"_npmUser":{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-secure-headers_2.0.0_1596879778246_0.5107514228113397"},"_hasShrinkwrap":false},"2.1.0":{"name":"next-secure-headers","version":"2.1.0","description":"Sets secure response headers for Next.js.","keywords":["Next.js","headers","security","csp"],"homepage":"https://github.com/jagaapple/next-secure-headers","bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","author":{"name":"Jaga Apple"},"contributors":[],"main":"lib/index.js","repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"scripts":{"prebuild":"rm -rf ./lib","build":"tsc","lint":"eslint ./src/**/*.ts","fix":"eslint --fix ./src/**/*.ts","prepublishOnly":"npm run build","test":"jest --coverage","coverage":"codecov","clean":"rm -rf ./lib ./coverage"},"config":{},"dependencies":{},"devDependencies":{"@types/jest":"^26.0.19","@types/jest-plugin-context":"^2.9.4","@types/node":"^14.14.16","@types/react":"^16.14.2","@typescript-eslint/eslint-plugin":"^4.11.0","@typescript-eslint/parser":"^4.11.0","codecov":"^3.8.1","eslint":"^7.16.0","eslint-config-prettier":"^7.1.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.3.0","jest":"^26.6.3","jest-plugin-context":"^2.9.0","prettier":"^2.2.1","react":"^16.14.0","ts-jest":"^26.4.4","typescript":"^4.1.3"},"peerDependencies":{},"engines":{"node":">=10.0.0"},"engineStrict":false,"preferGlobal":false,"private":false,"gitHead":"87f61296ecc501ec4745c89e77e5d6d52fd4a0d4","_id":"next-secure-headers@2.1.0","_nodeVersion":"12.20.0","_npmVersion":"7.0.15","dist":{"integrity":"sha512-52hskKwZ9s8K4ZGQglOdpSPtrVVRLKHGbxjQ2McnvJl0Iv7iQAFG9D42aWuRdueE0EEpdkuSNiQcJR0fIMSgTw==","shasum":"fca2b83f9f30ccec17443f8ca0fab79433edec5f","tarball":"https://registry.npmjs.org/next-secure-headers/-/next-secure-headers-2.1.0.tgz","fileCount":35,"unpackedSize":75000,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf552yCRA9TVsSAnZWagAArTgP/14gONMdl8D/mV3BiwJo\n+CSCmvtg36kIWn92G3sGRcbv1UVbW5NVUqUGYoO1/9whWsToqZMAUh2J0EJp\nM0WkQVIaNElCstwR8wxqRkxT+NOL2rQOVeBztYu/kVF19w7bqiU2d2HbbjVY\nHW30Wshjzms3b3+7g6UcM1xs40ix1v7tdiaf3W7rxmtYuOOvv5iByHSangOG\nWtELBFKGR6HBq51qpbRW6l1JEvTSyZmX0mud2Cq9BmYV/Kijymtycf/1nNl7\nGt5eNUXmhllNv9NnXjnjzI8re+hdLUEIQvM3UWDPGtACPJCVuyzroVO1QICG\nllN4tuUwv3w0KDhw6cJ0UAowXt8jyVTR/D7725b/iikujbRHCVQXHhHdy6lV\nrlEjek+sSpBu0Axtp1nMKziozOq2TA8UGIEyKvfhRaUxodon6zGfpV9uUIZR\nXSt1pndbyLxtGkhNRNAMlvjJUDntNiMSQuTeocgdHc4ZowqyQU89IoLnMblS\nRVM1RIYGiqUeI4C1KhgPKCsRwEw489Ajga5fy9Bp8MkooQBIwT4kDrQ/8j+/\nu8+w6/MgHWJRiEwa/B7oHaTCdiOlWTVBuz9VPP4ItJ3D6PamPnMVVKmiXnKZ\nr1exGrXo/WTdL2ZJwPOsMYz8S+IybnEZoWzrd+/QqHC12GDILYEULFMQxL4E\ncorZ\r\n=lZSf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGyfe8T+DZ0Cdyp8vQykQiQAAS3jDbdmwOZQolbVFKFfAiBKY2674YqgcZ2R+9Rl34PBaFaQ7Bx7ZF78zHg20pun/g=="}]},"_npmUser":{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"},"directories":{},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-secure-headers_2.1.0_1609014706060_0.5467662393719743"},"_hasShrinkwrap":false},"2.2.0":{"name":"next-secure-headers","version":"2.2.0","description":"Sets secure response headers for Next.js.","keywords":["Next.js","headers","security","csp"],"homepage":"https://github.com/jagaapple/next-secure-headers","bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","author":{"name":"Jaga Apple"},"contributors":[],"main":"lib/index.js","repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"scripts":{"prebuild":"rm -rf ./lib","build":"tsc","lint":"eslint ./src/**/*.ts","fix":"eslint --fix ./src/**/*.ts","prepublishOnly":"npm run build","test":"jest --coverage","coverage":"codecov","clean":"rm -rf ./lib ./coverage"},"config":{},"dependencies":{},"devDependencies":{"@types/jest":"^26.0.20","@types/jest-plugin-context":"^2.9.4","@types/node":"^14.14.31","@types/react":"^16.14.2","@typescript-eslint/eslint-plugin":"^4.15.2","@typescript-eslint/parser":"^4.15.2","codecov":"^3.8.1","eslint":"^7.20.0","eslint-config-prettier":"^8.1.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^3.3.1","jest":"^26.6.3","jest-plugin-context":"^2.9.0","prettier":"^2.2.1","react":"^16.14.0","ts-jest":"^26.5.2","typescript":"^4.1.3"},"peerDependencies":{},"engines":{"node":">=10.0.0"},"engineStrict":false,"preferGlobal":false,"private":false,"gitHead":"af1d1263a2e699e581f4ed0f9e69e7ec55f7f6f4","_id":"next-secure-headers@2.2.0","_nodeVersion":"12.20.0","_npmVersion":"7.0.15","dist":{"integrity":"sha512-C7OfZ9JdSJyYMz2ZBMI/WwNbt0qNjlFWX9afUp8nEUzbz6ez3JbeopdyxSZJZJAzVLIAfyk6n73rFpd4e22jRg==","shasum":"d4eb1b00a424f811c1455d1288990a4aad3026af","tarball":"https://registry.npmjs.org/next-secure-headers/-/next-secure-headers-2.2.0.tgz","fileCount":35,"unpackedSize":78425,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgN88ACRA9TVsSAnZWagAApb4P+wbHIjVDsz6XPGEMth1q\nkcNvLcmdWAyyGJge1+/nPA22/RmvoJFjMAnJ0fnfayW2tK7P0Z6Kq4VmW7gp\n6OZT/KPy3aaoXxd7v9v7dSYPxiwN3Y+qNvOa5dsOVIahWp3+ofUptRp0I+Pk\ndTpaRJGCiVAinsKN9gvg0NBp33zjtfXegx8XrE0MqbTrfahx2Rto1cSdUNN5\nwgnPbAUaniUVy8zaSMOICJRgAAft5WbO7hGB9F6fKjlxUJtzmdh6E6z6OXbE\nc5VNJmuOYrn+1zydgPJZk24ybPGCZUXrgRnKA9JO8NREbu6j0WbYqssHuOjf\n/JT9jZrh01NFpd+tZqvJr4nSwmD4Lg01/m8Tj4nVgDq4Lebq5OhKWu8+v4Qh\n2skxhvPEfr8KjidYSMfmAIKI06178Zb0Ws1HSfL6Rb6iYpxhU97Jhl14oNhq\na6azN2UGdVG0knCzh6MQMDUqbqmgoL3RzhupJehXUqIwdVyi59SAGh5QhZ1m\nbjxcWacZnWWl+Z+VrOpgzElOONR7H4Z87WWkJ/VvqPd0fvK/PtQPgC2ZSEtq\naMUK6FIrecOc5puZ/nwcQt6TYFuJ5JNaQCLeHntZTC4kY4yMPnycfuVcFJ6L\nrZ7F+AtHHMqbj3cohu0oh6O7fjiZ9rfHLJCkjSir7aL7zQ4olxRSzKczmNJk\n7BHg\r\n=CFjT\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICDuO9OD0i/h7Tq7mmYz6QK+cNJDyl3+CeHp5IcPxXCoAiEAvg6yZSGoY0/qQmM96SWMhFWG/4x5V1KCvuG1neg3soU="}]},"_npmUser":{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"},"directories":{},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/next-secure-headers_2.2.0_1614270207797_0.37673856212713175"},"_hasShrinkwrap":false}},"time":{"created":"2019-12-04T21:47:50.419Z","1.0.0":"2019-12-04T21:47:50.562Z","modified":"2022-05-10T15:03:03.422Z","1.0.1":"2019-12-13T17:28:56.681Z","2.0.0":"2020-08-08T09:42:58.368Z","2.1.0":"2020-12-26T20:31:46.263Z","2.2.0":"2021-02-25T16:23:28.036Z"},"maintainers":[{"name":"jagaapple","email":"jagaapple+npm@uniboar.com"}],"description":"Sets secure response headers for Next.js.","homepage":"https://github.com/jagaapple/next-secure-headers","keywords":["Next.js","headers","security","csp"],"repository":{"type":"git","url":"git+https://github.com/jagaapple/next-secure-headers.git"},"contributors":[],"author":{"name":"Jaga Apple"},"bugs":{"url":"https://github.com/jagaapple/next-secure-headers/issues"},"license":"MIT","readme":"<h1 align=\"center\">next-secure-headers</h1>\n\n<h4 align=\"center\">⛑️ Sets secure response headers for Next.js. 🌻</h4>\n\n```js\n// /next.config.js\n\nmodule.exports = {\n  async headers() {\n    return [{\n      source: \"/(.*)\",\n      headers: createSecureHeaders({\n        contentSecurityPolicy: {\n          directives: {\n            defaultSrc: \"'self'\",\n            styleSrc: [\"'self'\", \"https://stackpath.bootstrapcdn.com\"],\n          },\n        },\n        forceHTTPSRedirect: [true, { maxAge: 60 * 60 * 24 * 4, includeSubDomains: true }],\n        referrerPolicy: \"same-origin\",\n      })\n    }];\n  },\n};\n```\n\n<div align=\"center\">\n<a href=\"https://www.npmjs.com/package/next-secure-headers\"><img src=\"https://img.shields.io/npm/v/next-secure-headers.svg\" alt=\"npm\"></a>\n<a href=\"https://github.com/jagaapple/next-secure-headers/actions?query=workflow%3A%22Build+and+test%22\"><img src=\"https://github.com/jagaapple/next-secure-headers/workflows/Build%20and%20test/badge.svg\" alt=\"GitHub Actions\"></a>\n<a href=\"https://codecov.io/gh/jagaapple/next-secure-headers\"><img src=\"https://img.shields.io/codecov/c/github/jagaapple/next-secure-headers.svg\"></a>\n<a href=\"https://opensource.org/licenses/MIT\"><img src=\"https://img.shields.io/github/license/jagaapple/next-secure-headers.svg\" alt=\"license\"></a>\n<a href=\"https://twitter.com/jagaapple_tech\"><img src=\"https://img.shields.io/badge/contact-%40jagaapple_tech-blue.svg\" alt=\"@jagaapple_tech\"></a>\n</div>\n\n## Table of Contents\n\n<!-- TOC depthFrom:2 -->\n\n- [Table of Contents](#table-of-contents)\n- [Features](#features)\n  - [Why use next-secure-headers instead of Helmet?](#why-use-next-secure-headers-instead-of-helmet)\n    - [next-secure-headers vs Helmet](#next-secure-headers-vs-helmet)\n- [Quick Start](#quick-start)\n  - [Requirements](#requirements)\n  - [Installation](#installation)\n  - [Setup](#setup)\n    - [Use `createSecureHeaders` in `next.config.js` (RECOMMENDED)](#use-createsecureheaders-in-nextconfigjs-recommended)\n    - [Use `withSecureHeaders` in page components](#use-withsecureheaders-in-page-components)\n- [Rules](#rules)\n  - [`forceHTTPSRedirect`](#forcehttpsredirect)\n  - [`frameGuard`](#frameguard)\n  - [`noopen`](#noopen)\n  - [`nosniff`](#nosniff)\n  - [`xssProtection`](#xssprotection)\n  - [`contentSecurityPolicy`](#contentsecuritypolicy)\n  - [`expectCT`](#expectct)\n  - [`referrerPolicy`](#referrerpolicy)\n- [API](#api)\n  - [`createSecureHeaders`](#createsecureheaders)\n  - [`withSecureHeaders`](#withsecureheaders)\n  - [`createHeadersObject`](#createheadersobject)\n- [Recipes](#recipes)\n  - [How to remove X-Powered-By header](#how-to-remove-x-powered-by-header)\n  - [Overrides headers in a specific page using `withSecureHeaders`](#overrides-headers-in-a-specific-page-using-withsecureheaders)\n- [Contributing to next-secure-headers](#contributing-to-next-secure-headers)\n- [License](#license)\n\n<!-- /TOC -->\n\n\n## Features\n| FEATURES                    | WHAT YOU CAN DO                                         |\n|-----------------------------|---------------------------------------------------------|\n| ⚛️ **Designed for Next.js**  | Use for `next.config.js` or page components in `/pages` |\n| ✨ **Default applied rules** | Help your project even if you don't have knowledge      |\n| 🎩 **Type Safe**            | You can use with TypeScript                             |\n\n### Why use next-secure-headers instead of Helmet?\nnext-secure-headers is a similar to [Helmet](https://github.com/helmetjs/helmet), which sets HTTP response headers related to\nsecurity for Express.js.\n\nNext.js supports to be used in Node.js frameworks such as Express.js. So you can use Helmet with your Next.js project if you\ncreate a custom server, but the Next.js development team does not recommend a custom server.\nAlso, they are working to implement in order to be possible to use Next.js without a custom server. In fact, Next.js 9 supports\n[Dynamic Routing](https://github.com/zeit/next.js/#dynamic-routing), so we don't need to build a custom server in order to\nimplement it using such as [next-routes](https://github.com/fridays/next-routes), which requires a custom server.\n\n```js\n// /next.config.js\nconst { createSecureHeaders } = require(\"next-secure-headers\");\n\nmodule.exports = {\n  async headers() {\n    return [{ source: \"/(.*)\", headers: createSecureHeaders() }];\n  },\n};\n```\n\nIf you want to use Helmet, it requires to use a custom server against a recommended way. To solve this problem, next-secure-headers\nwas born. next-secure-headers is built for Next.js project so that you can specify any headers in `next.config.js` or page\ncomponents.\n\n#### next-secure-headers vs Helmet\nThe following are rules next-secure-headers has and Helmet has. next-secure-headers is inspired by Helmet, but it doesn't have\nsome rules for some reason.\n\n|                                   | next-secure-headers     | Helmet                  | Comment                                                                                           |\n|-----------------------------------|-------------------------|-------------------------|---------------------------------------------------------------------------------------------------|\n| Strict-Transport-Security         | `forceHTTPSRedirect`    | `hsts`                  |                                                                                                   |\n| X-Frame-Options                   | `frameGuard`            | `frameguard`            |                                                                                                   |\n| X-Download-Options                | `noopen`                | `ieNoOpen`              |                                                                                                   |\n| X-Content-Type-Options            | `nosniff`               | `noSniff`               |                                                                                                   |\n| X-XSS-Protection                  | `xssProtection`         | `xssFilter`             |                                                                                                   |\n| Content-Security-Policy           | `contentSecurityPolicy` | `contentSecurityPolicy` |                                                                                                   |\n| Expect-CT                         | `expectCT`              | `expectCt`              |                                                                                                   |\n| Referrer-Policy                   | `referrerPolicy`        | `referrerPolicy`        |                                                                                                   |\n| X-DNS-Prefetch-Control            | -                       | `dnsPrefetchControl`    | This has privacy implications but this improves performance.                                      |\n| Feature-Policy                    | -                       | `featurePolicy`         | Feature Policy improves security but it is working draft yet.                                     |\n| X-Powered-By                      | -                       | `hidePoweredBy`         | [Next.js supports to remove this header in `next.config.js`](#how-to-remove-x-powered-by-header). |\n| Related to cache                  | -                       | `nocache`               | As Helmet said, caching has lots of benefits.                                                     |\n| X-Permitted-Cross-Domain-Policies | -                       | `crossdomain`           | Adobe Flash is one of old web technologies.                                                       |\n\n\n## Quick Start\n### Requirements\n- npm or Yarn\n- Node.js 10.0.0 or higher\n- Next.js 8.0.0 or higher\n\n### Installation\n```bash\n$ npm install -D next-secure-headers\n```\n\nIf you are using Yarn, use the following command.\n\n```bash\n$ yarn add -D next-secure-headers\n```\n\n> ❗️ **For `withSecureHeaders` .**\n> If you want to use `withSecureHeaders` , you have to install without `-D` option (i.e., installing as `dependencies` not\n> `devDependencies` ).\n\n### Setup\nThere are two ways to specify headers.\nOne is to use `createSecureHeaders` in `next.config.js` , and another is to use `withSecureHeaders` in page components.\n\n#### Use `createSecureHeaders` in `next.config.js` (RECOMMENDED)\n> ❗️ **Next.js 9.5 or higher is required.**\n> `headers` function has been supported since Next.js 9.5, so you have to use Next.js 9.5 or higher if you want to use this way.\n\n> 🤔 **For Next.js 10 and I18n routes.**\n> If your project uses Next.js 10 and built-in I18n routes, and you want to apply rules for all pages, you have to specify\n> `\"/:path*\"` to `source` property instead of `\"/(.*)\"` .\n> Conversely, if your project doesn't use I18n routes even if using Next.js 10, you have to specify `\"/(.*)\"` instead.\n> These limitations are maybe bugs in Next.js .\n\nThis way uses `createSecureHeaders` function and [a built-in header configuration way by Next.js](https://nextjs.org/docs/api-reference/next.config.js/headers).\nThis is not required any servers, can be used in static pages, and can retain [Automatic Static Optimization](https://nextjs.org/docs/advanced-features/automatic-static-optimization).\nIf your project does not use any servers (using static pages or SSG) or you have just created a Next.js project, I recommend retaining static pages and adopting this way.\n\nImport `createSecureHeaders` from next-secure-headers and use it in `headers` async function in `next.config.js` .\n\n```js\n// /next.config.js\nconst { createSecureHeaders } = require(\"next-secure-headers\");\n\nmodule.exports = {\n  async headers() {\n    return [{ source: \"/(.*)\", headers: createSecureHeaders() }];\n  },\n};\n```\n\nBy default, next-secure-headers applies some rules. If you want to enable or disable rules, you can give options to the first\nargument of the function.\n\n```js\nmodule.exports = {\n  async headers() {\n    return [{\n      source: \"/(.*)\",\n      headers: createSecureHeaders({\n        contentSecurityPolicy: {\n          directives: {\n            defaultSrc: \"'self'\",\n            styleSrc: [\"'self'\", \"https://stackpath.bootstrapcdn.com\"],\n          },\n        },\n        forceHTTPSRedirect: [true, { maxAge: 60 * 60 * 24 * 4, includeSubDomains: true }],\n        referrerPolicy: \"same-origin\",\n      }),\n    }];\n  },\n};\n```\n\nAlso, you can configure different headers by URLs following [the official documents](https://nextjs.org/docs/api-reference/next.config.js/headers).\n\n#### Use `withSecureHeaders` in page components\n> ❗️ **Servers are required.**\n> This way requires any servers because `withSecureHeaders` uses `getServerSideProps` of Next.js.\n\nUse an exported function for your Next.js application in `/pages/_app.tsx` . Also, you can use in any page components in\n`/pages/xxx.tsx` instead.\n\n```ts\n// /pages/_app.tsx\nimport { withSecureHeaders } from \"next-secure-headers\";\n\nclass Application extends App {\n  ...\n}\n\nexport default withSecureHeaders()(Application);\n```\n\nBy default, next-secure-headers applies some rules. If you want to enable or disable rules, you can give options to the first\nargument of the function.\n\n```ts\nexport default withSecureHeaders({\n  contentSecurityPolicy: {\n    directives: {\n      defaultSrc: \"'self'\",\n      styleSrc: [\"'self'\", \"https://stackpath.bootstrapcdn.com\"],\n    },\n  },\n  forceHTTPSRedirect: [true, { maxAge: 60 * 60 * 24 * 4, includeSubDomains: true }],\n  referrerPolicy: \"same-origin\",\n})(Application);\n```\n\n\n## Rules\n### `forceHTTPSRedirect`\n```ts\n{\n  forceHTTPSRedirect: boolean | [true, Partial<{ maxAge: number; includeSubDomains: boolean; preload: boolean }>];\n}\n```\n\n| Default Value                  | MDN                                                                           |\n|--------------------------------|-------------------------------------------------------------------------------|\n| `[true, { maxAge: 63072000 }]` | https://developer.mozilla.org/docs/Web/HTTP/Headers/Strict-Transport-Security |\n\nThis is to set \"Strict-Transport-Security (HSTS)\" header and it's to prevent man-in-the-middle attacks during redirects from\nHTTP to HTTPS. To enable this is highly recommended if you use HTTPS (SSL) on your servers.\n\nYou can give `true` if you want to enable this rule, or you can specify options by giving `[true, OPTION_OBJECT]` . By default,\nthis sets `max-age` to two years (63,072,000 seconds).\n\n### `frameGuard`\n```ts\n{\n  frameGuard: false | \"deny\" | \"sameorigin\" | [\"allow-from\", { uri: string | URL }];\n}\n```\n\n| Default Value | MDN                                                                 |\n|---------------|---------------------------------------------------------------------|\n| `\"deny\"`      | https://developer.mozilla.org/docs/Web/HTTP/Headers/X-Frame-Options |\n\nThis is to set \"X-Frame-Options\" header and it's to prevent clickjacking attacks. `\"deny\"` is highly recommended if you don't\nuse frame elements such as `iframe` .\n\n### `noopen`\n```ts\n{\n  noopen: false | \"noopen\";\n}\n```\n\n| Default Value | MDN                                                                    |\n|---------------|------------------------------------------------------------------------|\n| `\"noopen\"`    | https://developer.mozilla.org/docs/Web/HTTP/Headers/X-Download-Options |\n\nThis is to set \"X-Download-Options\" header and it's to prevent to open downloaded files automatically for IE8+ (MIME Handling\nattacks).\n\n### `nosniff`\n```ts\n{\n  nosniff: false | \"nosniff\";\n}\n```\n\n| Default Value | MDN                                                                        |\n|---------------|----------------------------------------------------------------------------|\n| `\"nosniff\"`   | https://developer.mozilla.org/docs/Web/HTTP/Headers/X-Content-Type-Options |\n\nThis is to set \"X-Content-Type-Options\" header and it's to prevent MIME Sniffing attacks.\n\n### `xssProtection`\n```ts\n{\n  xssProtection: false | \"sanitize\" | \"block-rendering\" | [\"report\", { uri: string | URL }];\n}\n```\n\n| Default Value | MDN                                                                  |\n|---------------|----------------------------------------------------------------------|\n| `\"sanitize\"`  | https://developer.mozilla.org/docs/Web/HTTP/Headers/X-XSS-Protection |\n\nThis is to set \"X-XSS-Protection\" header and it's to prevent XSS attacks.\n\nIf you specify `\"sanitize\"` , this sets the header to `\"1\"` and browsers will sanitize unsafe area. If you specify\n`\"block-rendering\"` , this sets the header to `\"1; mode=block\"` and browsers will block rendering a page. \"X-XSS-Protection\"\nblocks many XSS attacks, but Content Security Policy is recommended to use compared to this.\n\n### `contentSecurityPolicy`\n```ts\n{\n  contentSecurityPolicy:\n    | false\n    | {\n        directives:\n          & Partial<{\n            childSrc: string | string[];\n            connectSrc: string | string[];\n            defaultSrc: string | string[];\n            fontSrc: string | string[];\n            frameSrc: string | string[];\n            imgSrc: string | string[];\n            manifestSrc: string | string[];\n            mediaSrc: string | string[];\n            prefetchSrc: string | string[];\n            objectSrc: string | string[];\n            scriptSrc: string | string[];\n            scriptSrcElem: string | string[];\n            scriptSrcAttr: string | string[];\n            styleSrc: string | string[];\n            styleSrcElem: string | string[];\n            styleSrcAttr: string | string[];\n            workerSrc: string | string[];\n          }>\n          & Partial<{\n            baseURI: string | string[];\n            pluginTypes: string | string[];\n            sandbox:\n              | true\n              | \"allow-downloads-without-user-activation\"\n              | \"allow-forms\"\n              | \"allow-modals\"\n              | \"allow-orientation-lock\"\n              | \"allow-pointer-lock\"\n              | \"allow-popups\"\n              | \"allow-popups-to-escape-sandbox\"\n              | \"allow-presentation\"\n              | \"allow-same-origin\"\n              | \"allow-scripts\"\n              | \"allow-storage-access-by-user-activation\"\n              | \"allow-top-navigation\"\n              | \"allow-top-navigation-by-user-activation\";\n          }>\n          & Partial<{\n            formAction: string | string[];\n            frameAncestors: string | string[];\n            navigateTo: string | string[];\n            reportURI: string | URL | (string | URL)[];\n            reportTo: string;\n          }>;\n        reportOnly?: boolean;\n      };\n}\n```\n\n| Default Value | MDN                                                                         |\n|---------------|-----------------------------------------------------------------------------|\n| `false`       | https://developer.mozilla.org/docs/Web/HTTP/Headers/Content-Security-Policy |\n\nThis is to set \"Content-Security-Policy\" or \"Content-Security-Policy-Report-Only\" header and it's to prevent to load and execute\nnon-allowed resources.\n\nIf you give true to `reportOnly` , this sets \"Content-Security-Policy-Report-Only\" to value instead of \"Content-Security-Policy\".\n\nAlso you can specify directives using chain-case names such as `child-src` instead of `childSrc` .\n\n> **❗️ When setting `frameAncestors` :X-Frame-Options takes priority.**\n> [Section \"Relation to X-Frame-Options\" of the CSP Spec](https://w3c.github.io/webappsec-csp/#frame-ancestors-and-frame-options) says: _\"If a resource is delivered with a policy that includes a directive named frame-ancestors and whose disposition is \"enforce\", then the X-Frame-Options header MUST be ignored\"_, but Chrome 40 & Firefox 35 ignore the frame-ancestors directive and follow the X-Frame-Options header instead.\n> \n> Therefore, if setting `frameAncestors` you should set `frameGuard` to `false`.\n\n### `expectCT`\n```ts\n{\n  expectCT: boolean | [true, Partial<{ maxAge: number; enforce: boolean; reportURI: string | URL }>];\n}\n```\n\n| Default Value | MDN                                                           |\n|---------------|---------------------------------------------------------------|\n| `false`       | https://developer.mozilla.org/docs/Web/HTTP/Headers/Expect-CT |\n\nThis is to set \"Expect-CT\" header and it's to tell browsers to expect Certificate Transparency.\n\n### `referrerPolicy`\n```ts\n{\n  referrerPolicy:\n    | false\n    | \"no-referrer\" | \"no-referrer-when-downgrade\" | \"origin\" | \"origin-when-cross-origin\" | \"same-origin\" | \"strict-origin\" | \"strict-origin-when-cross-origin\"\n    | (\"no-referrer\" | \"no-referrer-when-downgrade\" | \"origin\" | \"origin-when-cross-origin\" | \"same-origin\" | \"strict-origin\" | \"strict-origin-when-cross-origin\")[];\n}\n```\n\n| Default Value | MDN                                                                 |\n|---------------|---------------------------------------------------------------------|\n| `false`       | https://developer.mozilla.org/docs/Web/HTTP/Headers/Referrer-Policy |\n\nThis is to set \"Referrer-Policy\" header and it's to prevent to be got referrer by other servers. You can specify one or more\nvalues for legacy browsers which does not support a specific value.\n\n\n## API\n### `createSecureHeaders`\n```ts\nimport { createSecureHeaders } from \"next-secure-headers\";\n\ncreateSecureHeaders({ referrerPolicy: \"same-origin\" });\n// [\n//   {\n//     key: \"Referrer-Policy\",\n//     value: \"same-origin\",\n//   },\n// ]\n```\n\n`createSecureHeaders` is a function to return headers as object following a format like `{ key, value }` .\n\n```ts\ncreateSecureHeaders(OPTIONS);\n```\n\nThe first argument accepts options for rules.\n\n### `withSecureHeaders`\n```ts\nimport { withSecureHeaders } from \"next-secure-headers\";\n\nexport default withSecureHeaders({ referrerPolicy: \"same-origin\" })(Page);\n```\n\n`withSecureHeaders` is a HOC to specify headers using `getServerSideProps` . You can use this function for application\n( `/pages/_app.tsx` ) and page components ( `/pages/xxx.tsx` ). **THIS IS NOT AVAILBLE IN `next.config.js` .**\n\n```ts\nwithSecureHeaders(OPTIONS)(APPLICATION_OR_COMPONENT);\n```\n\nThe first argument accepts options for rules, and the argument of the returned function accepts application or page components.\nThe returned value is a new React component.\n\n### `createHeadersObject`\n```ts\nimport { createHeadersObject } from \"next-secure-headers\";\n\ncreateHeadersObject({ referrerPolicy: \"same-origin\" });\n// {\n//   \"Referrer-Policy\": \"same-origin\",\n// }\n```\n\n`createHeadersObject` is a function to return headers as object.\n\n```ts\ncreateHeadersObject(OPTIONS);\n```\n\nThe first argument accepts options for rules.\n\n\n## Recipes\n### How to remove X-Powered-By header\nIn general, X-Powered-By HTTP response header should be removed from response headers because it helps hackers to get the server\ninformation.\n\nnext-secure-headers does not support to remove X-Powered-By header, but Next.js supports to do.\n\n```ts\n// next.config.js\nmodule.exports = {\n  poweredByHeader: false,\n};\n```\n\nIf you give false to `poweredByHeader` in `next.config.js` , Next.js removes the header from response headers.\n\n### Overrides headers in a specific page using `withSecureHeaders`\n```ts\n// /pages/_app.tsx\nexport default withSecureHeaders({ referrerPolicy: \"same-origin\" })(Application);\n\n// /pages/about.tsx\nexport default withSecureHeaders({ referrerPolicy: \"no-referrer-when-downgrade\" })(Page);\n// But actually the server responds \"same-origin\"...\n```\n\nnext-secure-headers does not support to override response headers in child page components because of being restricted by Next.js\narchitecture.\n\n```ts\n// /config/secure-headers.ts\nimport { withSecureHeaders } from \"next-secure-headers\";\n\nexport const secureHeadersDefaultOption: Parameters<typeof withSecureHeaders>[0] = {\n  referrerPolicy: \"same-origin\",\n};\n\n// /pages/_app.tsx\nimport { secureHeadersDefaultOption } from \"../config/secure-headers\";\n\nexport default withSecureHeaders(secureHeadersDefaultOption)(Application);\n\n// /pages/about.tsx\nexport default withSecureHeaders({\n  ...secureHeadersDefaultOption,\n  referrerPolicy: \"no-referrer-when-downgrade\",\n})(Page);\n```\n\nTo solve this, you should define the option as one module, then you should import and merge the object.\n\n\n## Contributing to next-secure-headers\nBug reports and pull requests are welcome on GitHub at\n[https://github.com/jagaapple/next-secure-headers](https://github.com/jagaapple/next-secure-headers). This project\nis intended to be a safe, welcoming space for collaboration, and contributors are expected to adhere to the\n[Contributor Covenant](http://contributor-covenant.org) code of conduct.\n\nPlease read [Contributing Guidelines](./.github/CONTRIBUTING.md) before development and contributing.\n\n\n## License\nThe library is available as open source under the terms of the [MIT License](http://opensource.org/licenses/MIT).\n\nCopyright 2020 Jaga Apple. All rights reserved.\n","readmeFilename":"README.md"}