| 109 | }; |
| 110 | |
| 111 | export const initFastify = async (): Promise<FastifyAdapter> => { |
| 112 | const fastifyAdapter = new FastifyAdapter({ logger: isDevMode, bodyLimit: GRPC_MAX_PACKAGE_SIZE }); |
| 113 | await fastifyAdapter.register(fastifyMultipart as any); |
| 114 | // register helmet in fastify to avoid conflict with swagger |
| 115 | let helmetOptions: HelmetOptions = { |
| 116 | // update script-src to be compatible with swagger |
| 117 | contentSecurityPolicy: { |
| 118 | directives: { |
| 119 | 'default-src': ["'self'"], |
| 120 | 'base-uri': ["'self'"], |
| 121 | 'block-all-mixed-content': [], |
| 122 | 'font-src': ["'self'", 'https:', 'data:'], |
| 123 | 'frame-ancestors': ["'self'"], |
| 124 | 'img-src': ["'self'", 'data:'], |
| 125 | 'object-src': ["'none'"], |
| 126 | 'script-src': ["'self'", "'unsafe-inline'"], |
| 127 | 'script-src-attr': ["'none'"], |
| 128 | 'style-src': ["'self'", 'https:', "'unsafe-inline'"], |
| 129 | 'upgrade-insecure-requests': [], |
| 130 | }, |
| 131 | }, |
| 132 | }; |
| 133 | if (disableHSTS) { |
| 134 | helmetOptions = { ...helmetOptions, hsts: false } as any; |
| 135 | } |
| 136 | await fastifyAdapter.register(helmet as any, helmetOptions); |
| 137 | |
| 138 | return fastifyAdapter; |
| 139 | }; |
| 140 | |
| 141 | export const initHttpHook = (app: INestApplication) => { |
| 142 | const fastify = app.getHttpAdapter().getInstance() as FastifyInstance; |