github.com/EvanHahn/crystal-helmet

Help secure web apps with various HTTP headers

29 stars
0 dependents
License: MIT

Installation

# Add this to your shard.yml
dependencies:
  helmet:
    github: EvanHahn/crystal-helmet
    version: ~> 0.2.3

Then run:

shards install

shard.yml

Crystal
no constraint declared
License
MIT
Author
Evan Hahn <me@evanhahn.com>

Dependencies

This version declares no dependencies.

README

# Helmet

Helmet helps you secure your Crystal web apps by setting various HTTP headers. *It's not a silver bullet*, but it can help!

This is a port of the [Node.js version of Helmet](https://github.com/helmetjs/helmet).

## Installation


Add this to your application's `shard.yml`:

```yaml
dependencies:
  helmet:
    github: EvanHahn/crystal-helmet
```


## Usage


```crystal
require "http/server"
require "helmet"

server = HTTP::Server.new(
  [
    Helmet::DNSPrefetchControllerHandler.new,
    Helmet::FrameGuardHandler.new,
    Helmet::InternetExplorerNoOpenHandler.new,
    Helmet::NoSniffHandler.new,
    Helmet::StrictTransportSecurityHandler.new(7.day),
    Helmet::XSSFilterHandler.new,
  ]) do |context|
  context.response.content_type = "text/plain"
  context.response.print "Hello world!"
end

address = server.bind_tcp(8080)

server.listen
```


Helmet is really just a collection of smaller handlers that set HTTP headers. See them listed in the example above and in [the documentation](https://evanhahn.github.io/crystal-helmet/).


## Contributing


1. Fork it (https://github.com/EvanHahn/crystal-helmet/fork)
2. Create your branch (`git checkout -b my-new-feature`)
3. Commit your changes (`git commit -am 'Add XYZ'`)
4. Push to the branch (`git push origin my-new-feature`)
5. Create a new pull request


## Contributors


- [Evan Hahn](https://evanhahn.com) - creator, maintainer
- [Du Ba Thach](https://bthachdev.github.io/) - [#3](https://github.com/EvanHahn/crystal-helmet/pull/3)
- [Serdar Doğruyol](https://serdardogruyol.com/) - [#9](https://github.com/EvanHahn/crystal-helmet/pull/9)