disable CSP when env = development

This commit is contained in:
Danny Coates 2017-08-29 11:19:21 -07:00
parent ced640c24a
commit 74718d6361
No known key found for this signature in database
GPG Key ID: 4C442633C62E00CB

View File

@ -7,6 +7,7 @@ const storage = require('../storage');
const config = require('../config');
const pages = require('./pages');
// const lang = require('fluent-langneg')
const IS_DEV = config.env === 'development';
module.exports = function(app) {
app.use(
@ -18,9 +19,10 @@ module.exports = function(app) {
app.use(
helmet.hsts({
maxAge: 31536000,
force: config.env === 'production'
force: !IS_DEV
})
);
if (!IS_DEV) {
app.use(
helmet.contentSecurityPolicy({
directives: {
@ -41,6 +43,7 @@ module.exports = function(app) {
}
})
);
}
app.use(
busboy({
limits: {