{children}
diff --git a/examples/nextjs-app-dir-validate-email/middleware.ts b/examples/nextjs-app-dir-validate-email/middleware.ts
new file mode 100644
index 000000000..28c473b10
--- /dev/null
+++ b/examples/nextjs-app-dir-validate-email/middleware.ts
@@ -0,0 +1,8 @@
+import { createMiddleware } from "@nosecone/next";
+
+export const config = {
+ // matcher tells Next.js which routes to run the middleware on
+ matcher: ["/(.*)"],
+};
+
+export default createMiddleware();
diff --git a/examples/nextjs-app-dir-validate-email/package-lock.json b/examples/nextjs-app-dir-validate-email/package-lock.json
index 3c7ab53bd..be00e8539 100644
--- a/examples/nextjs-app-dir-validate-email/package-lock.json
+++ b/examples/nextjs-app-dir-validate-email/package-lock.json
@@ -9,6 +9,7 @@
"version": "0.1.0",
"dependencies": {
"@arcjet/next": "file:../../arcjet-next",
+ "@nosecone/next": "file:../../nosecone-next",
"next": "15.0.1",
"react": "^18",
"react-dom": "^18"
@@ -56,6 +57,24 @@
"next": ">=13"
}
},
+ "../../nosecone-next": {
+ "version": "1.0.0-alpha.28",
+ "license": "Apache-2.0",
+ "dependencies": {
+ "nosecone": "1.0.0-alpha.28"
+ },
+ "devDependencies": {
+ "@arcjet/eslint-config": "1.0.0-alpha.28",
+ "@arcjet/rollup-config": "1.0.0-alpha.28",
+ "@arcjet/tsconfig": "1.0.0-alpha.28",
+ "@rollup/wasm-node": "4.24.4",
+ "@types/node": "18.18.0",
+ "typescript": "5.6.3"
+ },
+ "engines": {
+ "node": ">=18"
+ }
+ },
"node_modules/@aashutoshrathi/word-wrap": {
"version": "1.2.6",
"resolved": "https://registry.npmjs.org/@aashutoshrathi/word-wrap/-/word-wrap-1.2.6.tgz",
@@ -788,6 +807,10 @@
"node": ">= 8"
}
},
+ "node_modules/@nosecone/next": {
+ "resolved": "../../nosecone-next",
+ "link": true
+ },
"node_modules/@rtsao/scc": {
"version": "1.1.0",
"resolved": "https://registry.npmjs.org/@rtsao/scc/-/scc-1.1.0.tgz",
diff --git a/examples/nextjs-app-dir-validate-email/package.json b/examples/nextjs-app-dir-validate-email/package.json
index c4b7f4e0a..58bfe6d7b 100644
--- a/examples/nextjs-app-dir-validate-email/package.json
+++ b/examples/nextjs-app-dir-validate-email/package.json
@@ -10,6 +10,7 @@
},
"dependencies": {
"@arcjet/next": "file:../../arcjet-next",
+ "@nosecone/next": "file:../../nosecone-next",
"next": "15.0.1",
"react": "^18",
"react-dom": "^18"
diff --git a/examples/sveltekit/package-lock.json b/examples/sveltekit/package-lock.json
index 6eec024ef..bb93e5edc 100644
--- a/examples/sveltekit/package-lock.json
+++ b/examples/sveltekit/package-lock.json
@@ -8,7 +8,8 @@
"name": "sveltekit",
"version": "0.0.1",
"dependencies": {
- "@arcjet/sveltekit": "file:../../arcjet-sveltekit"
+ "@arcjet/sveltekit": "file:../../arcjet-sveltekit",
+ "@nosecone/sveltekit": "file:../../nosecone-sveltekit"
},
"devDependencies": {
"@sveltejs/adapter-auto": "^3.3.1",
@@ -57,6 +58,25 @@
"node": ">=18"
}
},
+ "../../nosecone-sveltekit": {
+ "name": "@nosecone/sveltekit",
+ "version": "1.0.0-alpha.28",
+ "license": "Apache-2.0",
+ "dependencies": {
+ "nosecone": "1.0.0-alpha.28"
+ },
+ "devDependencies": {
+ "@arcjet/eslint-config": "1.0.0-alpha.28",
+ "@arcjet/rollup-config": "1.0.0-alpha.28",
+ "@arcjet/tsconfig": "1.0.0-alpha.28",
+ "@rollup/wasm-node": "4.24.4",
+ "@types/node": "18.18.0",
+ "typescript": "5.6.3"
+ },
+ "engines": {
+ "node": ">=18"
+ }
+ },
"node_modules/@ampproject/remapping": {
"version": "2.3.0",
"resolved": "https://registry.npmjs.org/@ampproject/remapping/-/remapping-2.3.0.tgz",
@@ -660,6 +680,10 @@
"node": ">= 8"
}
},
+ "node_modules/@nosecone/sveltekit": {
+ "resolved": "../../nosecone-sveltekit",
+ "link": true
+ },
"node_modules/@polka/url": {
"version": "1.0.0-next.28",
"resolved": "https://registry.npmjs.org/@polka/url/-/url-1.0.0-next.28.tgz",
diff --git a/examples/sveltekit/package.json b/examples/sveltekit/package.json
index adb97fb3b..600b0d767 100644
--- a/examples/sveltekit/package.json
+++ b/examples/sveltekit/package.json
@@ -13,7 +13,8 @@
"format": "prettier --write ."
},
"dependencies": {
- "@arcjet/sveltekit": "file:../../arcjet-sveltekit"
+ "@arcjet/sveltekit": "file:../../arcjet-sveltekit",
+ "@nosecone/sveltekit": "file:../../nosecone-sveltekit"
},
"devDependencies": {
"@sveltejs/adapter-auto": "^3.3.1",
diff --git a/examples/sveltekit/src/hooks.server.ts b/examples/sveltekit/src/hooks.server.ts
index a64616e99..27ed6d07f 100644
--- a/examples/sveltekit/src/hooks.server.ts
+++ b/examples/sveltekit/src/hooks.server.ts
@@ -1,27 +1,25 @@
import { aj } from "$lib/server/arcjet";
import { error } from "@sveltejs/kit";
-import type { RequestEvent } from "@sveltejs/kit";
+import { createHook } from "@nosecone/sveltekit";
+import { sequence } from "@sveltejs/kit/hooks";
-export async function handle({
- event,
- resolve,
-}: {
- event: RequestEvent;
- resolve: (event: RequestEvent) => Response | Promise;
-}): Promise {
- // Ignore routes that extend the Arcjet rules - they will call `.protect` themselves
- const filteredRoutes = ["/api/rate-limited", "/rate-limited"];
- if (filteredRoutes.includes(event.url.pathname)) {
- // return - route will handle protection
- return resolve(event);
- }
+export const handle = sequence(
+ createHook(),
+ async ({ event, resolve }) => {
+ // Ignore routes that extend the Arcjet rules - they will call `.protect` themselves
+ const filteredRoutes = ["/api/rate-limited", "/rate-limited"];
+ if (filteredRoutes.includes(event.url.pathname)) {
+ // return - route will handle protection
+ return resolve(event);
+ }
- // Ensure every other route is protected with shield
- const decision = await aj.protect(event);
- if (decision.isDenied()) {
- return error(403, "Forbidden");
- }
+ // Ensure every other route is protected with shield
+ const decision = await aj.protect(event);
+ if (decision.isDenied()) {
+ return error(403, "Forbidden");
+ }
- // Continue with the route
- return resolve(event);
-}
\ No newline at end of file
+ // Continue with the route
+ return await resolve(event);
+ }
+)
diff --git a/examples/sveltekit/svelte.config.js b/examples/sveltekit/svelte.config.js
index 973bdc965..3e19f2738 100644
--- a/examples/sveltekit/svelte.config.js
+++ b/examples/sveltekit/svelte.config.js
@@ -1,5 +1,6 @@
import adapter from "@sveltejs/adapter-auto";
import { vitePreprocess } from "@sveltejs/vite-plugin-svelte";
+import { csp } from "@nosecone/sveltekit"
/** @type {import('@sveltejs/kit').Config} */
const config = {
@@ -8,6 +9,7 @@ const config = {
preprocess: vitePreprocess(),
kit: {
+ csp: csp(),
// adapter-auto only supports some environments, see https://kit.svelte.dev/docs/adapter-auto for a list.
// If your environment is not supported, or you settled on a specific environment, switch out the adapter.
// See https://kit.svelte.dev/docs/adapters for more information about adapters.
diff --git a/nosecone-next/.eslintignore b/nosecone-next/.eslintignore
new file mode 100644
index 000000000..9cfa2cae7
--- /dev/null
+++ b/nosecone-next/.eslintignore
@@ -0,0 +1,6 @@
+/.turbo/
+/coverage/
+/node_modules/
+*.d.ts
+*.js
+!*.config.js
diff --git a/nosecone-next/.eslintrc.cjs b/nosecone-next/.eslintrc.cjs
new file mode 100644
index 000000000..abe4cd7b4
--- /dev/null
+++ b/nosecone-next/.eslintrc.cjs
@@ -0,0 +1,4 @@
+module.exports = {
+ root: true,
+ extends: ["@arcjet/eslint-config"],
+};
diff --git a/nosecone-next/.gitignore b/nosecone-next/.gitignore
new file mode 100644
index 000000000..35b162da3
--- /dev/null
+++ b/nosecone-next/.gitignore
@@ -0,0 +1,135 @@
+# Logs
+logs
+*.log
+npm-debug.log*
+yarn-debug.log*
+yarn-error.log*
+lerna-debug.log*
+.pnpm-debug.log*
+
+# Diagnostic reports (https://nodejs.org/api/report.html)
+report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json
+
+# Runtime data
+pids
+*.pid
+*.seed
+*.pid.lock
+
+# Directory for instrumented libs generated by jscoverage/JSCover
+lib-cov
+
+# Coverage directory used by tools like istanbul
+coverage
+*.lcov
+
+# nyc test coverage
+.nyc_output
+
+# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
+.grunt
+
+# Bower dependency directory (https://bower.io/)
+bower_components
+
+# node-waf configuration
+.lock-wscript
+
+# Compiled binary addons (https://nodejs.org/api/addons.html)
+build/Release
+
+# Dependency directories
+node_modules/
+jspm_packages/
+
+# Snowpack dependency directory (https://snowpack.dev/)
+web_modules/
+
+# TypeScript cache
+*.tsbuildinfo
+
+# Optional npm cache directory
+.npm
+
+# Optional eslint cache
+.eslintcache
+
+# Optional stylelint cache
+.stylelintcache
+
+# Microbundle cache
+.rpt2_cache/
+.rts2_cache_cjs/
+.rts2_cache_es/
+.rts2_cache_umd/
+
+# Optional REPL history
+.node_repl_history
+
+# Output of 'npm pack'
+*.tgz
+
+# Yarn Integrity file
+.yarn-integrity
+
+# dotenv environment variable files
+.env
+.env.development.local
+.env.test.local
+.env.production.local
+.env.local
+
+# parcel-bundler cache (https://parceljs.org/)
+.cache
+.parcel-cache
+
+# Next.js build output
+.next
+out
+
+# Nuxt.js build / generate output
+.nuxt
+dist
+
+# Gatsby files
+.cache/
+# Comment in the public line in if your project uses Gatsby and not Next.js
+# https://nextjs.org/blog/next-9-1#public-directory-support
+# public
+
+# vuepress build output
+.vuepress/dist
+
+# vuepress v2.x temp and cache directory
+.temp
+.cache
+
+# Docusaurus cache and generated files
+.docusaurus
+
+# Serverless directories
+.serverless/
+
+# FuseBox cache
+.fusebox/
+
+# DynamoDB Local files
+.dynamodb/
+
+# TernJS port file
+.tern-port
+
+# Stores VSCode versions used for testing VSCode extensions
+.vscode-test
+
+# yarn v2
+.yarn/cache
+.yarn/unplugged
+.yarn/build-state.yml
+.yarn/install-state.gz
+.pnp.*
+
+# Generated files
+index.js
+index.d.ts
+test/*.js
diff --git a/nosecone-next/LICENSE b/nosecone-next/LICENSE
new file mode 100644
index 000000000..261eeb9e9
--- /dev/null
+++ b/nosecone-next/LICENSE
@@ -0,0 +1,201 @@
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
diff --git a/nosecone-next/README.md b/nosecone-next/README.md
new file mode 100644
index 000000000..a6038eb02
--- /dev/null
+++ b/nosecone-next/README.md
@@ -0,0 +1,67 @@
+
+
+
+
+# `@nosecone/next`
+
+
+
+Protect your Next.js application with secure headers.
+
+## Installation
+
+```shell
+npm install -S @nosecone/next
+```
+
+## Example
+
+Create a `middleware.ts` file with the contents:
+
+```ts
+import { createMiddleware } from "@nosecone/next";
+
+export const config = {
+ // matcher tells Next.js to run middleware on all routes
+ matcher: ["/(.*)"],
+};
+
+export default createMiddleware();
+```
+
+Add `await connection()` in your `app/layout.tsx` file:
+
+```diff
++ import { connection } from "next/server";
+
+export default async function RootLayout({
+ children,
+}: {
+ children: React.ReactNode;
+}) {
++ // Opt-out of static generation for every page so the CSP nonce can be applied
++ await connection()
+
+ return (
+
+ {children}
+
+ );
+}
+```
+
+## License
+
+Licensed under the [Apache License, Version 2.0][apache-license].
+
+[apache-license]: http://www.apache.org/licenses/LICENSE-2.0
diff --git a/nosecone-next/index.ts b/nosecone-next/index.ts
new file mode 100644
index 000000000..67b6d8bfe
--- /dev/null
+++ b/nosecone-next/index.ts
@@ -0,0 +1,110 @@
+import nosecone, { defaults } from "nosecone";
+import type { CspDirectives, NoseconeOptions } from "nosecone";
+
+// We export `nosecone` as the default so it can be used with `new Response()`
+export default nosecone;
+
+function nonce() {
+ return `'nonce-${btoa(crypto.randomUUID())}'` as const;
+}
+
+const defaultDirectives = defaults.contentSecurityPolicy.directives;
+
+function applyNextDefaults(options: NoseconeOptions): NoseconeOptions {
+ if (
+ typeof options.contentSecurityPolicy === "undefined" ||
+ !options.contentSecurityPolicy
+ ) {
+ return options;
+ }
+
+ const directives =
+ options.contentSecurityPolicy === true ||
+ typeof options.contentSecurityPolicy.directives === "undefined"
+ ? defaultDirectives
+ : options.contentSecurityPolicy.directives;
+
+ let scriptSrc: CspDirectives["scriptSrc"];
+ if (directives.scriptSrc === true) {
+ scriptSrc = defaultDirectives.scriptSrc;
+ } else {
+ scriptSrc = directives.scriptSrc;
+ }
+ if (scriptSrc) {
+ const scriptSrcSet = new Set(scriptSrc);
+ scriptSrcSet.delete("'self'");
+ scriptSrcSet.add(nonce());
+ scriptSrcSet.add("'strict-dynamic'");
+ // Next.js hot reloading relies on `eval` so we enable it in development
+ if (process.env.NODE_ENV === "development") {
+ scriptSrcSet.add("'unsafe-eval'");
+ }
+ scriptSrc = Array.from(scriptSrcSet);
+ }
+
+ let styleSrc: CspDirectives["styleSrc"];
+ if (directives.styleSrc === true) {
+ styleSrc = defaultDirectives.styleSrc;
+ } else {
+ styleSrc = directives.styleSrc;
+ }
+ if (styleSrc) {
+ const styleSrcSet = new Set(styleSrc);
+ styleSrcSet.add("'unsafe-inline'");
+ styleSrc = Array.from(styleSrcSet);
+ }
+
+ return {
+ ...options,
+ contentSecurityPolicy: {
+ directives: {
+ ...directives,
+ scriptSrc,
+ styleSrc,
+ },
+ },
+ };
+}
+
+// Setting specific headers is the way that Next.js implements middleware
+// See: https://github.com/vercel/next.js/blob/5c45d58cd058a9683e435fd3a1a9b8fede8376c3/packages/next/src/server/web/spec-extension/response.ts#L148
+function nextMiddlewareHeaders(
+ headers: Record,
+): Record {
+ const forwardedHeaders: Record = {
+ "x-middleware-next": "1",
+ };
+
+ // This applies the logic to forward headers from Next.js middleware
+ // https://github.com/vercel/next.js/blob/5c45d58cd058a9683e435fd3a1a9b8fede8376c3/packages/next/src/server/web/spec-extension/response.ts#L22-L27
+ for (const [headerName, headerValue] of Object.entries(headers)) {
+ if (typeof headerValue !== "string") {
+ throw new Error(`impossible: missing value for ${headerName}`);
+ }
+ forwardedHeaders[`x-middleware-request-${headerName}`] = headerValue;
+ }
+ forwardedHeaders["x-middleware-override-headers"] =
+ Object.keys(headers).join(",");
+
+ return forwardedHeaders;
+}
+
+/**
+ * Create Next.js middleware that sets secure headers on every request.
+ *
+ * @param options: Configuration to provide to Nosecone
+ * @returns Next.js middleware that sets secure headers
+ */
+export function createMiddleware(options: NoseconeOptions = defaults) {
+ return async () => {
+ const opts = applyNextDefaults(options);
+ const headers = nosecone(opts);
+
+ return new Response(null, {
+ headers: {
+ ...headers,
+ ...nextMiddlewareHeaders(headers),
+ },
+ });
+ };
+}
diff --git a/nosecone-next/package.json b/nosecone-next/package.json
new file mode 100644
index 000000000..0e78892db
--- /dev/null
+++ b/nosecone-next/package.json
@@ -0,0 +1,61 @@
+{
+ "name": "@nosecone/next",
+ "version": "1.0.0-alpha.28",
+ "description": "Protect your Next.js application with secure headers",
+ "license": "Apache-2.0",
+ "homepage": "https://arcjet.com",
+ "repository": {
+ "type": "git",
+ "url": "git+https://github.com/arcjet/arcjet-js.git",
+ "directory": "nosecone-next"
+ },
+ "bugs": {
+ "url": "https://github.com/arcjet/arcjet-js/issues",
+ "email": "support@arcjet.com"
+ },
+ "author": {
+ "name": "Arcjet",
+ "email": "support@arcjet.com",
+ "url": "https://arcjet.com"
+ },
+ "engines": {
+ "node": ">=18"
+ },
+ "type": "module",
+ "main": "./index.js",
+ "types": "./index.d.ts",
+ "files": [
+ "LICENSE",
+ "README.md",
+ "*.js",
+ "*.d.ts",
+ "*.ts",
+ "!*.config.js"
+ ],
+ "scripts": {
+ "prepublishOnly": "npm run build",
+ "build": "rollup --config rollup.config.js",
+ "lint": "eslint .",
+ "pretest": "npm run build",
+ "test": "node --test"
+ },
+ "dependencies": {
+ "nosecone": "1.0.0-alpha.28"
+ },
+ "peerDependencies": {
+ "next": ">=14"
+ },
+ "devDependencies": {
+ "@arcjet/eslint-config": "1.0.0-alpha.28",
+ "@arcjet/rollup-config": "1.0.0-alpha.28",
+ "@arcjet/tsconfig": "1.0.0-alpha.28",
+ "@rollup/wasm-node": "4.24.4",
+ "@types/node": "18.18.0",
+ "next": "15.0.1",
+ "typescript": "5.6.3"
+ },
+ "publishConfig": {
+ "access": "public",
+ "tag": "latest"
+ }
+}
diff --git a/nosecone-next/rollup.config.js b/nosecone-next/rollup.config.js
new file mode 100644
index 000000000..79177f236
--- /dev/null
+++ b/nosecone-next/rollup.config.js
@@ -0,0 +1,3 @@
+import { createConfig } from "@arcjet/rollup-config";
+
+export default createConfig(import.meta.url);
diff --git a/nosecone-next/tsconfig.json b/nosecone-next/tsconfig.json
new file mode 100644
index 000000000..95929e097
--- /dev/null
+++ b/nosecone-next/tsconfig.json
@@ -0,0 +1,4 @@
+{
+ "extends": "@arcjet/tsconfig/base",
+ "include": ["index.ts", "test/*.ts"]
+}
diff --git a/nosecone-sveltekit/.eslintignore b/nosecone-sveltekit/.eslintignore
new file mode 100644
index 000000000..9cfa2cae7
--- /dev/null
+++ b/nosecone-sveltekit/.eslintignore
@@ -0,0 +1,6 @@
+/.turbo/
+/coverage/
+/node_modules/
+*.d.ts
+*.js
+!*.config.js
diff --git a/nosecone-sveltekit/.eslintrc.cjs b/nosecone-sveltekit/.eslintrc.cjs
new file mode 100644
index 000000000..abe4cd7b4
--- /dev/null
+++ b/nosecone-sveltekit/.eslintrc.cjs
@@ -0,0 +1,4 @@
+module.exports = {
+ root: true,
+ extends: ["@arcjet/eslint-config"],
+};
diff --git a/nosecone-sveltekit/.gitignore b/nosecone-sveltekit/.gitignore
new file mode 100644
index 000000000..35b162da3
--- /dev/null
+++ b/nosecone-sveltekit/.gitignore
@@ -0,0 +1,135 @@
+# Logs
+logs
+*.log
+npm-debug.log*
+yarn-debug.log*
+yarn-error.log*
+lerna-debug.log*
+.pnpm-debug.log*
+
+# Diagnostic reports (https://nodejs.org/api/report.html)
+report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json
+
+# Runtime data
+pids
+*.pid
+*.seed
+*.pid.lock
+
+# Directory for instrumented libs generated by jscoverage/JSCover
+lib-cov
+
+# Coverage directory used by tools like istanbul
+coverage
+*.lcov
+
+# nyc test coverage
+.nyc_output
+
+# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
+.grunt
+
+# Bower dependency directory (https://bower.io/)
+bower_components
+
+# node-waf configuration
+.lock-wscript
+
+# Compiled binary addons (https://nodejs.org/api/addons.html)
+build/Release
+
+# Dependency directories
+node_modules/
+jspm_packages/
+
+# Snowpack dependency directory (https://snowpack.dev/)
+web_modules/
+
+# TypeScript cache
+*.tsbuildinfo
+
+# Optional npm cache directory
+.npm
+
+# Optional eslint cache
+.eslintcache
+
+# Optional stylelint cache
+.stylelintcache
+
+# Microbundle cache
+.rpt2_cache/
+.rts2_cache_cjs/
+.rts2_cache_es/
+.rts2_cache_umd/
+
+# Optional REPL history
+.node_repl_history
+
+# Output of 'npm pack'
+*.tgz
+
+# Yarn Integrity file
+.yarn-integrity
+
+# dotenv environment variable files
+.env
+.env.development.local
+.env.test.local
+.env.production.local
+.env.local
+
+# parcel-bundler cache (https://parceljs.org/)
+.cache
+.parcel-cache
+
+# Next.js build output
+.next
+out
+
+# Nuxt.js build / generate output
+.nuxt
+dist
+
+# Gatsby files
+.cache/
+# Comment in the public line in if your project uses Gatsby and not Next.js
+# https://nextjs.org/blog/next-9-1#public-directory-support
+# public
+
+# vuepress build output
+.vuepress/dist
+
+# vuepress v2.x temp and cache directory
+.temp
+.cache
+
+# Docusaurus cache and generated files
+.docusaurus
+
+# Serverless directories
+.serverless/
+
+# FuseBox cache
+.fusebox/
+
+# DynamoDB Local files
+.dynamodb/
+
+# TernJS port file
+.tern-port
+
+# Stores VSCode versions used for testing VSCode extensions
+.vscode-test
+
+# yarn v2
+.yarn/cache
+.yarn/unplugged
+.yarn/build-state.yml
+.yarn/install-state.gz
+.pnp.*
+
+# Generated files
+index.js
+index.d.ts
+test/*.js
diff --git a/nosecone-sveltekit/LICENSE b/nosecone-sveltekit/LICENSE
new file mode 100644
index 000000000..261eeb9e9
--- /dev/null
+++ b/nosecone-sveltekit/LICENSE
@@ -0,0 +1,201 @@
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
diff --git a/nosecone-sveltekit/README.md b/nosecone-sveltekit/README.md
new file mode 100644
index 000000000..f330e3422
--- /dev/null
+++ b/nosecone-sveltekit/README.md
@@ -0,0 +1,70 @@
+
+
+
+
+# `@nosecone/sveltekit`
+
+
+
+Protect your SvelteKit application with secure headers.
+
+## Installation
+
+```shell
+npm install -S @nosecone/sveltekit
+```
+
+## Example
+
+Update your `svelte.config.js` file for `csp`:
+
+```diff
+import adapter from "@sveltejs/adapter-auto";
+import { vitePreprocess } from "@sveltejs/vite-plugin-svelte";
++ import { csp } from "@nosecone/sveltekit"
+
+/** @type {import('@sveltejs/kit').Config} */
+const config = {
+ // Consult https://kit.svelte.dev/docs/integrations#preprocessors
+ // for more information about preprocessors
+ preprocess: vitePreprocess(),
+
+ kit: {
++ csp: csp(),
+ // adapter-auto only supports some environments, see https://kit.svelte.dev/docs/adapter-auto for a list.
+ // If your environment is not supported, or you settled on a specific environment, switch out the adapter.
+ // See https://kit.svelte.dev/docs/adapters for more information about adapters.
+ adapter: adapter(),
+ },
+};
+
+export default config;
+```
+
+Create a `src/hooks.server.ts` file with the contents:
+
+```ts
+import { createHook } from "@nosecone/sveltekit";
+import { sequence } from "@sveltejs/kit/hooks";
+
+export const handle = sequence(
+ createHook(),
+ // ... other hooks can go here
+);
+```
+
+## License
+
+Licensed under the [Apache License, Version 2.0][apache-license].
+
+[apache-license]: http://www.apache.org/licenses/LICENSE-2.0
diff --git a/nosecone-sveltekit/index.ts b/nosecone-sveltekit/index.ts
new file mode 100644
index 000000000..1ad332d8f
--- /dev/null
+++ b/nosecone-sveltekit/index.ts
@@ -0,0 +1,116 @@
+import nosecone, {
+ CONTENT_SECURITY_POLICY_DIRECTIVES,
+ QUOTED,
+ defaults,
+ NoseconeValidationError,
+} from "nosecone";
+import type { CspDirectives, NoseconeOptions } from "nosecone";
+import type { Handle, KitConfig } from "@sveltejs/kit";
+
+// We export `nosecone` as the default so it can be used with `new Response()`
+export default nosecone;
+
+/**
+ * Create a SvelteKit hook that sets secure headers on every request.
+ *
+ * @param options: Configuration to provide to Nosecone
+ * @returns A SvelteKit hook that sets secure headers
+ */
+export function createHook(options: NoseconeOptions = defaults): Handle {
+ return async ({ event, resolve }) => {
+ const response = await resolve(event);
+
+ const headers = nosecone(options);
+ for (const [headerName, headerValue] of Object.entries(headers)) {
+ // Only add headers that aren't already set. For example, SvelteKit will
+ // likely have added `Content-Security-Policy` if configured with `csp`
+ if (!response.headers.has(headerName)) {
+ response.headers.set(headerName, headerValue);
+ }
+ }
+
+ return response;
+ };
+}
+
+type SvelteKitCsp = Exclude;
+
+export type ContentSecurityPolicyConfig = {
+ mode?: SvelteKitCsp["mode"];
+ directives?: CspDirectives;
+ // TODO: Support `reportOnly`
+};
+
+const directives: CspDirectives = {
+ ...defaults.contentSecurityPolicy.directives,
+ scriptSrc: ["'strict-dynamic'"],
+};
+
+function unquote(value?: string) {
+ for (const [unquoted, quoted] of QUOTED) {
+ if (value === quoted) {
+ return unquoted;
+ }
+ }
+
+ return value;
+}
+
+function resolveValue(v: (() => string) | string) {
+ if (typeof v === "function") {
+ return v();
+ } else {
+ return v;
+ }
+}
+
+function directivesToSvelteKitConfig(
+ directives: Readonly,
+): SvelteKitCsp["directives"] {
+ const sveltekitDirectives: SvelteKitCsp["directives"] = {};
+ for (const [optionKey, optionValues] of Object.entries(directives)) {
+ const key = CONTENT_SECURITY_POLICY_DIRECTIVES.get(
+ // @ts-expect-error because we're validating this option key
+ optionKey,
+ );
+ if (!key) {
+ throw new NoseconeValidationError(
+ `${optionKey} is not a Content-Security-Policy directive`,
+ );
+ }
+
+ // Skip anything falsey
+ if (!optionValues) {
+ continue;
+ }
+
+ // TODO: What do we want to do if array is empty? I think they work differently for some directives
+ const resolvedValues = Array.isArray(optionValues)
+ ? new Set(optionValues.map(resolveValue))
+ : new Set();
+
+ // TODO: Add validations for SvelteKit CSP directives
+
+ const values = Array.from(resolvedValues);
+
+ if (key === "upgrade-insecure-requests") {
+ sveltekitDirectives[key] = true;
+ } else {
+ // @ts-ignore because we're mapping to SvelteKit options
+ sveltekitDirectives[key] = values.map(unquote);
+ }
+ }
+
+ return sveltekitDirectives;
+}
+
+export function csp(
+ options: ContentSecurityPolicyConfig = { mode: "auto", directives },
+): SvelteKitCsp {
+ return {
+ mode: options.mode ? options.mode : "auto",
+ directives: directivesToSvelteKitConfig(
+ options.directives ?? defaults.contentSecurityPolicy.directives,
+ ),
+ };
+}
diff --git a/nosecone-sveltekit/package.json b/nosecone-sveltekit/package.json
new file mode 100644
index 000000000..94957f7bf
--- /dev/null
+++ b/nosecone-sveltekit/package.json
@@ -0,0 +1,61 @@
+{
+ "name": "@nosecone/sveltekit",
+ "version": "1.0.0-alpha.28",
+ "description": "Protect your SvelteKit application with secure headers",
+ "license": "Apache-2.0",
+ "homepage": "https://arcjet.com",
+ "repository": {
+ "type": "git",
+ "url": "git+https://github.com/arcjet/arcjet-js.git",
+ "directory": "nosecone-sveltekit"
+ },
+ "bugs": {
+ "url": "https://github.com/arcjet/arcjet-js/issues",
+ "email": "support@arcjet.com"
+ },
+ "author": {
+ "name": "Arcjet",
+ "email": "support@arcjet.com",
+ "url": "https://arcjet.com"
+ },
+ "engines": {
+ "node": ">=18"
+ },
+ "type": "module",
+ "main": "./index.js",
+ "types": "./index.d.ts",
+ "files": [
+ "LICENSE",
+ "README.md",
+ "*.js",
+ "*.d.ts",
+ "*.ts",
+ "!*.config.js"
+ ],
+ "scripts": {
+ "prepublishOnly": "npm run build",
+ "build": "rollup --config rollup.config.js",
+ "lint": "eslint .",
+ "pretest": "npm run build",
+ "test": "node --test"
+ },
+ "dependencies": {
+ "nosecone": "1.0.0-alpha.28"
+ },
+ "peerDependencies": {
+ "@sveltejs/kit": ">=2"
+ },
+ "devDependencies": {
+ "@arcjet/eslint-config": "1.0.0-alpha.28",
+ "@arcjet/rollup-config": "1.0.0-alpha.28",
+ "@arcjet/tsconfig": "1.0.0-alpha.28",
+ "@rollup/wasm-node": "4.24.4",
+ "@sveltejs/kit": "^2.8.0",
+ "@types/node": "18.18.0",
+ "typescript": "5.6.3"
+ },
+ "publishConfig": {
+ "access": "public",
+ "tag": "latest"
+ }
+}
diff --git a/nosecone-sveltekit/rollup.config.js b/nosecone-sveltekit/rollup.config.js
new file mode 100644
index 000000000..79177f236
--- /dev/null
+++ b/nosecone-sveltekit/rollup.config.js
@@ -0,0 +1,3 @@
+import { createConfig } from "@arcjet/rollup-config";
+
+export default createConfig(import.meta.url);
diff --git a/nosecone-sveltekit/tsconfig.json b/nosecone-sveltekit/tsconfig.json
new file mode 100644
index 000000000..95929e097
--- /dev/null
+++ b/nosecone-sveltekit/tsconfig.json
@@ -0,0 +1,4 @@
+{
+ "extends": "@arcjet/tsconfig/base",
+ "include": ["index.ts", "test/*.ts"]
+}
diff --git a/nosecone/.eslintignore b/nosecone/.eslintignore
new file mode 100644
index 000000000..9cfa2cae7
--- /dev/null
+++ b/nosecone/.eslintignore
@@ -0,0 +1,6 @@
+/.turbo/
+/coverage/
+/node_modules/
+*.d.ts
+*.js
+!*.config.js
diff --git a/nosecone/.eslintrc.cjs b/nosecone/.eslintrc.cjs
new file mode 100644
index 000000000..abe4cd7b4
--- /dev/null
+++ b/nosecone/.eslintrc.cjs
@@ -0,0 +1,4 @@
+module.exports = {
+ root: true,
+ extends: ["@arcjet/eslint-config"],
+};
diff --git a/nosecone/.gitignore b/nosecone/.gitignore
new file mode 100644
index 000000000..35b162da3
--- /dev/null
+++ b/nosecone/.gitignore
@@ -0,0 +1,135 @@
+# Logs
+logs
+*.log
+npm-debug.log*
+yarn-debug.log*
+yarn-error.log*
+lerna-debug.log*
+.pnpm-debug.log*
+
+# Diagnostic reports (https://nodejs.org/api/report.html)
+report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json
+
+# Runtime data
+pids
+*.pid
+*.seed
+*.pid.lock
+
+# Directory for instrumented libs generated by jscoverage/JSCover
+lib-cov
+
+# Coverage directory used by tools like istanbul
+coverage
+*.lcov
+
+# nyc test coverage
+.nyc_output
+
+# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
+.grunt
+
+# Bower dependency directory (https://bower.io/)
+bower_components
+
+# node-waf configuration
+.lock-wscript
+
+# Compiled binary addons (https://nodejs.org/api/addons.html)
+build/Release
+
+# Dependency directories
+node_modules/
+jspm_packages/
+
+# Snowpack dependency directory (https://snowpack.dev/)
+web_modules/
+
+# TypeScript cache
+*.tsbuildinfo
+
+# Optional npm cache directory
+.npm
+
+# Optional eslint cache
+.eslintcache
+
+# Optional stylelint cache
+.stylelintcache
+
+# Microbundle cache
+.rpt2_cache/
+.rts2_cache_cjs/
+.rts2_cache_es/
+.rts2_cache_umd/
+
+# Optional REPL history
+.node_repl_history
+
+# Output of 'npm pack'
+*.tgz
+
+# Yarn Integrity file
+.yarn-integrity
+
+# dotenv environment variable files
+.env
+.env.development.local
+.env.test.local
+.env.production.local
+.env.local
+
+# parcel-bundler cache (https://parceljs.org/)
+.cache
+.parcel-cache
+
+# Next.js build output
+.next
+out
+
+# Nuxt.js build / generate output
+.nuxt
+dist
+
+# Gatsby files
+.cache/
+# Comment in the public line in if your project uses Gatsby and not Next.js
+# https://nextjs.org/blog/next-9-1#public-directory-support
+# public
+
+# vuepress build output
+.vuepress/dist
+
+# vuepress v2.x temp and cache directory
+.temp
+.cache
+
+# Docusaurus cache and generated files
+.docusaurus
+
+# Serverless directories
+.serverless/
+
+# FuseBox cache
+.fusebox/
+
+# DynamoDB Local files
+.dynamodb/
+
+# TernJS port file
+.tern-port
+
+# Stores VSCode versions used for testing VSCode extensions
+.vscode-test
+
+# yarn v2
+.yarn/cache
+.yarn/unplugged
+.yarn/build-state.yml
+.yarn/install-state.gz
+.pnp.*
+
+# Generated files
+index.js
+index.d.ts
+test/*.js
diff --git a/nosecone/LICENSE b/nosecone/LICENSE
new file mode 100644
index 000000000..261eeb9e9
--- /dev/null
+++ b/nosecone/LICENSE
@@ -0,0 +1,201 @@
+ Apache License
+ Version 2.0, January 2004
+ http://www.apache.org/licenses/
+
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+ 1. Definitions.
+
+ "License" shall mean the terms and conditions for use, reproduction,
+ and distribution as defined by Sections 1 through 9 of this document.
+
+ "Licensor" shall mean the copyright owner or entity authorized by
+ the copyright owner that is granting the License.
+
+ "Legal Entity" shall mean the union of the acting entity and all
+ other entities that control, are controlled by, or are under common
+ control with that entity. For the purposes of this definition,
+ "control" means (i) the power, direct or indirect, to cause the
+ direction or management of such entity, whether by contract or
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
+ outstanding shares, or (iii) beneficial ownership of such entity.
+
+ "You" (or "Your") shall mean an individual or Legal Entity
+ exercising permissions granted by this License.
+
+ "Source" form shall mean the preferred form for making modifications,
+ including but not limited to software source code, documentation
+ source, and configuration files.
+
+ "Object" form shall mean any form resulting from mechanical
+ transformation or translation of a Source form, including but
+ not limited to compiled object code, generated documentation,
+ and conversions to other media types.
+
+ "Work" shall mean the work of authorship, whether in Source or
+ Object form, made available under the License, as indicated by a
+ copyright notice that is included in or attached to the work
+ (an example is provided in the Appendix below).
+
+ "Derivative Works" shall mean any work, whether in Source or Object
+ form, that is based on (or derived from) the Work and for which the
+ editorial revisions, annotations, elaborations, or other modifications
+ represent, as a whole, an original work of authorship. For the purposes
+ of this License, Derivative Works shall not include works that remain
+ separable from, or merely link (or bind by name) to the interfaces of,
+ the Work and Derivative Works thereof.
+
+ "Contribution" shall mean any work of authorship, including
+ the original version of the Work and any modifications or additions
+ to that Work or Derivative Works thereof, that is intentionally
+ submitted to Licensor for inclusion in the Work by the copyright owner
+ or by an individual or Legal Entity authorized to submit on behalf of
+ the copyright owner. For the purposes of this definition, "submitted"
+ means any form of electronic, verbal, or written communication sent
+ to the Licensor or its representatives, including but not limited to
+ communication on electronic mailing lists, source code control systems,
+ and issue tracking systems that are managed by, or on behalf of, the
+ Licensor for the purpose of discussing and improving the Work, but
+ excluding communication that is conspicuously marked or otherwise
+ designated in writing by the copyright owner as "Not a Contribution."
+
+ "Contributor" shall mean Licensor and any individual or Legal Entity
+ on behalf of whom a Contribution has been received by Licensor and
+ subsequently incorporated within the Work.
+
+ 2. Grant of Copyright License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ copyright license to reproduce, prepare Derivative Works of,
+ publicly display, publicly perform, sublicense, and distribute the
+ Work and such Derivative Works in Source or Object form.
+
+ 3. Grant of Patent License. Subject to the terms and conditions of
+ this License, each Contributor hereby grants to You a perpetual,
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+ (except as stated in this section) patent license to make, have made,
+ use, offer to sell, sell, import, and otherwise transfer the Work,
+ where such license applies only to those patent claims licensable
+ by such Contributor that are necessarily infringed by their
+ Contribution(s) alone or by combination of their Contribution(s)
+ with the Work to which such Contribution(s) was submitted. If You
+ institute patent litigation against any entity (including a
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
+ or a Contribution incorporated within the Work constitutes direct
+ or contributory patent infringement, then any patent licenses
+ granted to You under this License for that Work shall terminate
+ as of the date such litigation is filed.
+
+ 4. Redistribution. You may reproduce and distribute copies of the
+ Work or Derivative Works thereof in any medium, with or without
+ modifications, and in Source or Object form, provided that You
+ meet the following conditions:
+
+ (a) You must give any other recipients of the Work or
+ Derivative Works a copy of this License; and
+
+ (b) You must cause any modified files to carry prominent notices
+ stating that You changed the files; and
+
+ (c) You must retain, in the Source form of any Derivative Works
+ that You distribute, all copyright, patent, trademark, and
+ attribution notices from the Source form of the Work,
+ excluding those notices that do not pertain to any part of
+ the Derivative Works; and
+
+ (d) If the Work includes a "NOTICE" text file as part of its
+ distribution, then any Derivative Works that You distribute must
+ include a readable copy of the attribution notices contained
+ within such NOTICE file, excluding those notices that do not
+ pertain to any part of the Derivative Works, in at least one
+ of the following places: within a NOTICE text file distributed
+ as part of the Derivative Works; within the Source form or
+ documentation, if provided along with the Derivative Works; or,
+ within a display generated by the Derivative Works, if and
+ wherever such third-party notices normally appear. The contents
+ of the NOTICE file are for informational purposes only and
+ do not modify the License. You may add Your own attribution
+ notices within Derivative Works that You distribute, alongside
+ or as an addendum to the NOTICE text from the Work, provided
+ that such additional attribution notices cannot be construed
+ as modifying the License.
+
+ You may add Your own copyright statement to Your modifications and
+ may provide additional or different license terms and conditions
+ for use, reproduction, or distribution of Your modifications, or
+ for any such Derivative Works as a whole, provided Your use,
+ reproduction, and distribution of the Work otherwise complies with
+ the conditions stated in this License.
+
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
+ any Contribution intentionally submitted for inclusion in the Work
+ by You to the Licensor shall be under the terms and conditions of
+ this License, without any additional terms or conditions.
+ Notwithstanding the above, nothing herein shall supersede or modify
+ the terms of any separate license agreement you may have executed
+ with Licensor regarding such Contributions.
+
+ 6. Trademarks. This License does not grant permission to use the trade
+ names, trademarks, service marks, or product names of the Licensor,
+ except as required for reasonable and customary use in describing the
+ origin of the Work and reproducing the content of the NOTICE file.
+
+ 7. Disclaimer of Warranty. Unless required by applicable law or
+ agreed to in writing, Licensor provides the Work (and each
+ Contributor provides its Contributions) on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+ implied, including, without limitation, any warranties or conditions
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+ PARTICULAR PURPOSE. You are solely responsible for determining the
+ appropriateness of using or redistributing the Work and assume any
+ risks associated with Your exercise of permissions under this License.
+
+ 8. Limitation of Liability. In no event and under no legal theory,
+ whether in tort (including negligence), contract, or otherwise,
+ unless required by applicable law (such as deliberate and grossly
+ negligent acts) or agreed to in writing, shall any Contributor be
+ liable to You for damages, including any direct, indirect, special,
+ incidental, or consequential damages of any character arising as a
+ result of this License or out of the use or inability to use the
+ Work (including but not limited to damages for loss of goodwill,
+ work stoppage, computer failure or malfunction, or any and all
+ other commercial damages or losses), even if such Contributor
+ has been advised of the possibility of such damages.
+
+ 9. Accepting Warranty or Additional Liability. While redistributing
+ the Work or Derivative Works thereof, You may choose to offer,
+ and charge a fee for, acceptance of support, warranty, indemnity,
+ or other liability obligations and/or rights consistent with this
+ License. However, in accepting such obligations, You may act only
+ on Your own behalf and on Your sole responsibility, not on behalf
+ of any other Contributor, and only if You agree to indemnify,
+ defend, and hold each Contributor harmless for any liability
+ incurred by, or claims asserted against, such Contributor by reason
+ of your accepting any such warranty or additional liability.
+
+ END OF TERMS AND CONDITIONS
+
+ APPENDIX: How to apply the Apache License to your work.
+
+ To apply the Apache License to your work, attach the following
+ boilerplate notice, with the fields enclosed by brackets "[]"
+ replaced with your own identifying information. (Don't include
+ the brackets!) The text should be enclosed in the appropriate
+ comment syntax for the file format. We also recommend that a
+ file or class name and description of purpose be included on the
+ same "printed page" as the copyright notice for easier
+ identification within third-party archives.
+
+ Copyright [yyyy] [name of copyright owner]
+
+ Licensed under the Apache License, Version 2.0 (the "License");
+ you may not use this file except in compliance with the License.
+ You may obtain a copy of the License at
+
+ http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
diff --git a/nosecone/README.md b/nosecone/README.md
new file mode 100644
index 000000000..556579c34
--- /dev/null
+++ b/nosecone/README.md
@@ -0,0 +1,41 @@
+
+
+
+
+# `nosecone`
+
+
+
+Protect your `Response` with secure headers.
+
+## Installation
+
+```shell
+npm install -S nosecone
+```
+
+## Example
+
+```ts
+import nosecone from "nosecone";
+
+const secureResponse = new Response(null, {
+ headers: nosecone(),
+});
+```
+
+## License
+
+Licensed under the [Apache License, Version 2.0][apache-license].
+
+[apache-license]: http://www.apache.org/licenses/LICENSE-2.0
diff --git a/nosecone/index.ts b/nosecone/index.ts
new file mode 100644
index 000000000..3ef84f339
--- /dev/null
+++ b/nosecone/index.ts
@@ -0,0 +1,700 @@
+// Types based on
+// https://github.com/josh-hemphill/csp-typed-directives/blob/6e2cbc6d3cc18bbdc9b13d42c4556e786e28b243/src/csp.types.ts
+//
+// MIT License
+//
+// Copyright (c) 2021-present, Joshua Hemphill
+// Copyright (c) 2021, Tecnico Corporation
+//
+// Permission is hereby granted, free of charge, to any person obtaining a copy
+// of this software and associated documentation files (the "Software"), to deal
+// in the Software without restriction, including without limitation the rights
+// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+// copies of the Software, and to permit persons to whom the Software is
+// furnished to do so, subject to the following conditions:
+//
+// The above copyright notice and this permission notice shall be included in all
+// copies or substantial portions of the Software.
+//
+// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+// SOFTWARE.
+
+export type ActionSource = "'strict-dynamic'" | "'report-sample'";
+export type BaseSource =
+ | "'self'"
+ | "'unsafe-eval'"
+ | "'unsafe-hashes'"
+ | "'unsafe-inline'"
+ | "'wasm-unsafe-eval'"
+ | "'none'";
+export type CryptoSource =
+ `'${"nonce" | "sha256" | "sha384" | "sha512"}-${string}'`;
+export type FrameSource = HostSource | SchemeSource | "'self'" | "'none'";
+export type HostNameScheme = `${string}.${string}` | "localhost";
+export type HostSource = `${HostProtocolSchemes}${HostNameScheme}${PortScheme}`;
+export type HostProtocolSchemes = `${string}://` | "";
+export type PortScheme = `:${number}` | "" | ":*";
+export type SchemeSource =
+ | "http:"
+ | "https:"
+ | "data:"
+ | "mediastream:"
+ | "blob:"
+ | "filesystem:";
+export type Source = HostSource | SchemeSource | CryptoSource | BaseSource;
+export type StaticOrDynamic = boolean | null | ReadonlyArray S)>;
+
+export interface CspDirectives {
+ baseUri?: StaticOrDynamic