SecurityHeaders class final

Adds the response headers a browser uses to lock a page down.

None of these are a substitute for the server being correct; each one turns a class of mistake into a smaller one.

final app = Router()
  ..layer(const SecurityHeaders())
  ..merge(routes);

Every value is replaceable, and a null drops the header entirely — a default that cannot be turned off is a default that gets forked.

Implemented types

Constructors

SecurityHeaders({String? contentTypeOptions = 'nosniff', String? frameOptions = 'DENY', String? referrerPolicy = 'strict-origin-when-cross-origin', String? contentSecurityPolicy, String? strictTransportSecurity})
Adds the usual set.
const

Properties

contentSecurityPolicy → String?
A content security policy, when the application has one.
final
contentTypeOptions → String?
Stops a browser guessing a type other than the one you sent.
final
frameOptions → String?
Stops the page being framed, which is what clickjacking needs.
final
hashCode → int
The hash code for this object.
no setterinherited
referrerPolicy → String?
How much of the URL to leak when following a link off-site.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
strictTransportSecurity → String?
Tells a browser to use HTTPS for this host from now on.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toMiddleware() → Middleware
Builds the shelf middleware this value configures.
override
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited