|
|
|
|
|
|
|
|
*/ |
|
|
*/ |
|
|
|
|
|
|
|
|
// Security |
|
|
// Security |
|
|
app.disable ('x-powered-by'); // TODO: recherche warum? |
|
|
|
|
|
|
|
|
app.disable ('x-powered-by'); // TODO: Disable Header information: Powerd by Express -> Information disclosure |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/* |
|
|
/* |
|
|
|
|
|
|
|
|
//app.use ('/api', api_routes); |
|
|
//app.use ('/api', api_routes); |
|
|
|
|
|
|
|
|
// Static Files |
|
|
// Static Files |
|
|
app.use (express.static(__dirname + '/public')); |
|
|
|
|
|
|
|
|
app.use (express.static(__dirname + '/public')); // Allow server access to 'public' folder |
|
|
|
|
|
|
|
|
// Other stuff is NOT authorized unless logged in |
|
|
// Other stuff is NOT authorized unless logged in |
|
|
//app.use (authorize.genCheckAuthorized ('user')); |
|
|
//app.use (authorize.genCheckAuthorized ('user')); |