helmetjs/helmet ? reverse-engineered prompt

Reverse engineered prompt

Build me a small TypeScript library for Express that makes it easy to secure an app with the usual HTTP headers.

I want a single middleware I can add with one line, and it should set the common security headers by default, like content security policy, strict transport security, clickjacking protection, and the other standard ones. It should also let me turn any header off, or pass options to customize things like the content security policy directives.

Please make it work in a simple Express app, keep it easy to use, and include a clear README example that shows the default setup and a couple of common customizations. If there are tricky browser or development cases, handle them sensibly and document them. Look up the current docs online if you need to, but keep the API straightforward and low maintenance.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab