fix: remove duplicate configuration for helmet-hsts

v1.18.x
Julian Lam 5 years ago
parent ad68a338c4
commit 0f10e0836b

@ -164,9 +164,7 @@ function setupExpressApp(app) {
saveUninitialized: nconf.get('sessionSaveUninitialized') || false,
}));
app.use(helmet({
hsts: !!meta.config['hsts-enabled'],
}));
app.use(helmet());
app.use(helmet.referrerPolicy({ policy: 'strict-origin-when-cross-origin' }));
if (meta.config['hsts-enabled']) {
app.use(helmet.hsts({

Loading…
Cancel
Save