Skip to content

Commit b2aed38

Browse files
authored
Merge pull request #286 from cfabianski/patch-1
doc: annotate server.js with extra info regarding session and static …
2 parents ea58b51 + ea13d3f commit b2aed38

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

server.js

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,8 @@ MongoClient.connect(db, (err, db) => {
116116
app.engine(".html", consolidate.swig);
117117
app.set("view engine", "html");
118118
app.set("views", `${__dirname}/app/views`);
119+
// Fix for A5 - Security MisConfig
120+
// TODO: make sure assets are declared before app.use(session())
119121
app.use(express.static(`${__dirname}/app/assets`));
120122

121123

0 commit comments

Comments
 (0)