Protect your SvelteKit application with secure headers
npm install @nosecone/sveltekit@nosecone/sveltekitProtect your SvelteKit application with secure headers.
- npm package (@nosecone/sveltekit)
- GitHub source code (nosecone-sveltekit/ in arcjet/arcjet-js)
This is our adapter to integrate Nosecone into SvelteKit.
Nosecone makes it easy to add and configure security headers.
This package exists so that we can provide the best possible experience to
SvelteKit users.
You can use this package with or without Arcjet to protect your app if you are
using SvelteKit.
Use [@nosecone/next][github-nosecone-next] if you use Next.js and
use [nosecone][github-nosecone] itself if you use a different framework.
This package is ESM only.
Install with npm in Node.js:
``sh`
npm install @nosecone/sveltekit
Configure csp from Nosecone in svelte.config.js:
`diff
+import { csp } from "@nosecone/sveltekit"
import adapter from "@sveltejs/adapter-auto";
import { vitePreprocess } from "@sveltejs/vite-plugin-svelte";
/* @type {import('@sveltejs/kit').Config} /
const config = {
kit: {
// adapter-auto only supports some environments, see https://kit.svelte.dev/docs/adapter-auto for a list.
// If your environment is not supported, or you settled on a specific environment, switch out the adapter.
// See https://kit.svelte.dev/docs/adapters for more information about adapters.
adapter: adapter(),
+ csp: csp(),
},
// Consult https://kit.svelte.dev/docs/integrations#preprocessors
// for more information about preprocessors
preprocess: vitePreprocess(),
};
export default config;
`
…then use createHook from Nosecone in a src/hooks.server.ts file:
`ts
import { createHook } from "@nosecone/sveltekit";
import { sequence } from "@sveltejs/kit/hooks";
export const handle = sequence(
createHook(),
// ... other hooks can go here
);
``
[Apache License, Version 2.0][apache-license] © [Arcjet Labs, Inc.][arcjet]
[apache-license]: http://www.apache.org/licenses/LICENSE-2.0
[arcjet]: https://arcjet.com
[github-nosecone-next]: https://github.com/arcjet/arcjet-js/tree/main/nosecone-next
[github-nosecone]: https://github.com/arcjet/arcjet-js/tree/main/nosecone