Description
Helmet sets security HTTP headers for Express applications. Depending on the version, its framing option may be named frameguard or xFrameOptions. Setting a header option such as this or contentSecurityPolicy (CSP) to false stops Helmet from providing that header. Without equivalent policies elsewhere, this can weaken defenses against clickjacking or script injection. Disabling CSP does not create XSS on its own.
Potential impact
- Without framing restrictions, an attacker may embed a page in an iframe and trick users into clicking unintended actions.
- Without an effective CSP, fewer restrictions limit malicious script loading and execution if a script injection vulnerability exists.
Remediation
- Keep the default protections from
app.use(helmet())where possible. Check the headers actually returned by the application or proxy. - Restrict framing origins with
X-Frame-Optionsor CSP'sframe-ancestors, using options appropriate for your Helmet version. Their protections overlap, so evaluate the policies together in the final response. - Limit CSP to required sources. Where needed, use nonce- or hash-based policies instead of broad
*,'unsafe-inline', or'unsafe-eval'allowances. - Apply exceptions only to pages that need external frames or scripts.
Examples
Before
javascript
const express = require("express");
const helmet = require("helmet");
const app = express();
// Before: disable both framing headers and CSP in this middleware.
app.use(helmet({
xFrameOptions: false,
contentSecurityPolicy: false,
}));
app.get("/pay", (req, res) => {
res.send('<button id="pay">결제하기</button>');
});
app.listen(3000);
After
javascript
const express = require("express");
const helmet = require("helmet");
const app = express();
// After: enable Helmet with restrictive CSP and framing policies.
app.use(
helmet({
// Older Helmet versions use frameguard: { action: "sameorigin" }.
xFrameOptions: { action: "sameorigin" },
contentSecurityPolicy: {
useDefaults: true,
directives: {
"default-src": ["'self'"],
"script-src": ["'self'"], // Disallow inline scripts and arbitrary external sources.
"object-src": ["'none'"],
"frame-ancestors": ["'self'"], // Restrict framing origins.
},
},
})
);
app.get("/pay", (req, res) => {
res.send('<button id="pay">결제하기</button>');
});
app.listen(3000);
Explanation:
- Before: One Helmet configuration disables both
X-Frame-Optionsand CSP. Both headers are absent unless another layer provides them. - After: Policies allow only same-origin frames and scripts. Adjust them to the service's requirements and Helmet version.