Skip to content

Conversation

@DulanjaliSKoswatte
Copy link

@DulanjaliSKoswatte DulanjaliSKoswatte commented May 9, 2020

Fixes CWE 16 and CWE 264 in stackle-api

Changes proposed in the pull request

Stackle-master\stackle_api\server.js

const helmet = require('helmet')
app.use(helmet.frameguard())

app.use(function (err, req, res, next) {
res.header("Access-Control-Allow-Origin", "http://localhost:8080");
res.header('Access-Control-Allow-Methods', 'GET, PUT, POST, DELETE, OPTIONS');
res.header("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept");
console.error(err.stack);
res.status(500).send('Something broke!')
});

Impact

HTTP Header level validation

Other information

Check if you have done the following before creating the PR

  • console logs have been deleted
  • No commented code (If commented the reasons are given)

Stackle-master.zip
Cross-Domain Misconfiguration.docx
X-Frame-Options Header Not Set.docx

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants