import assert from "node:assert/strict"; import { test } from "node:test"; import { securityHeaders } from "./security-headers.ts"; test("securityHeaders: strict zero-JS defaults; HSTS only over https", () => { const h = securityHeaders(); // Always-on hardening, independent of scheme. assert.equal(h["x-content-type-options"], "nosniff"); assert.equal(h["x-frame-options"], "DENY"); assert.equal(h["referrer-policy"], "strict-origin-when-cross-origin"); assert.equal(h["cross-origin-opener-policy"], "same-origin"); const csp = h["content-security-policy"] ?? ""; assert.match(csp, /default-src 'self'/); assert.match(csp, /script-src 'self'/); // a plugin may ship its own JS; the core ships none assert.doesNotMatch(csp, /script-src[^;]*'unsafe-inline'/); // an injected