|
|
@ -125,6 +125,10 @@ var express = require('express'),
|
|
|
|
app.use(function (req, res, next) {
|
|
|
|
app.use(function (req, res, next) {
|
|
|
|
nconf.set('https', req.secure);
|
|
|
|
nconf.set('https', req.secure);
|
|
|
|
res.locals.csrf_token = req.session._csrf;
|
|
|
|
res.locals.csrf_token = req.session._csrf;
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
// Disable framing
|
|
|
|
|
|
|
|
res.setHeader("X-Frame-Options", "DENY");
|
|
|
|
|
|
|
|
|
|
|
|
next();
|
|
|
|
next();
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
|
|