ya isntala y da menor errores en desarrollo, aun no es perfecto pero ta bien
This commit is contained in:
@@ -42,9 +42,12 @@ export default defineEventHandler(async (event) => {
|
||||
setHeader(event, 'Cache-Control', 'public, max-age=3600') // 1 hour cache
|
||||
setHeader(event, 'Accept-Ranges', 'bytes')
|
||||
|
||||
// Add security headers
|
||||
// Add security headers (but allow DevTools)
|
||||
setHeader(event, 'X-Content-Type-Options', 'nosniff')
|
||||
setHeader(event, 'X-Frame-Options', 'DENY')
|
||||
// Don't set X-Frame-Options DENY for development
|
||||
if (process.env.NODE_ENV === 'production') {
|
||||
setHeader(event, 'X-Frame-Options', 'DENY')
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user