forked from mozilla/srihash.org
-
Notifications
You must be signed in to change notification settings - Fork 0
/
index.js
116 lines (102 loc) · 2.7 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
/* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
'use strict';
var Path = require('path');
var Hapi = require('hapi');
var vision = require('vision');
var inert = require('inert');
var handlebars = require('handlebars');
handlebars = require('handlebars-helper-sri').register(handlebars);
var helpers = require('./lib/helpers.js');
var server = new Hapi.Server();
var CSP_HEADER = "default-src 'none'; img-src 'self'; style-src 'self'; font-src 'self' ; frame-src 'self'"; // jshint ignore:line
server.connection({
port: process.env.PORT || 4000,
routes: { security: { xframe: 'sameorigin' } }
});
server.register(vision, function () {
server.views({
engines: {
html: handlebars
},
path: Path.join(__dirname, 'templates')
});
});
server.register(inert, function () {
/**
* Serve index.js
*/
server.route({
method: 'GET',
path: '/',
handler: function (request, reply) {
var browsers = helpers.shuffleArray([
{ 'name': 'Firefox', 'url': 'https://www.mozilla.org/firefox/' },
{ 'name': 'Chrome', 'url': 'https://www.google.com/chrome/browser/desktop/' }
]);
reply
.view('index', { 'title': 'SRI Hash Generator', 'browsers': browsers })
.header('Content-Security-Policy', CSP_HEADER);
}
});
/**
* Serve public files
*/
server.route({
method: 'GET',
path: '/{param*}',
handler: {
directory: {
path: 'public',
etagMethod: false,
lookupCompressed: true
}
},
config: {
cache: {
expiresIn: 60 * 60 * 1000 // 1 hour
}
}
});
/**
* Return SRI lookup in JSON format
*/
server.route({
method: 'POST',
path: '/generate',
handler: function (request, reply) {
var options = {
url: request.payload.url,
algorithms: request.payload.algorithms
};
helpers.generate(options, function (result) {
reply(
JSON.stringify(result)
).type('application/json');
});
}
});
/**
* Return SRI lookup in HTML format.
* Deprecated, pending move to isomorphic app.
*/
server.route({
method: 'POST',
path: '/hash',
handler: function (request, reply) {
helpers.generateElement(
request.payload.url,
request.payload.algorithms,
function (result) {
reply
.view('hash', { 'hash': result })
.header('Content-Security-Policy', CSP_HEADER);
}
);
}
});
});
server.start(function () {
console.log('Server running at:', server.info.uri);
});