| 1 | /** |
| 2 | * /.well-known/security.txt (RFC 9116): where to report a vulnerability. |
| 3 | * Its `Expires` is computed, so it never goes stale. |
| 4 | */ |
| 5 | import type { Route } from "./+types/security-txt"; |
| 6 | import { securityTxt } from "../lib/legal"; |
| 7 | |
| 8 | export function loader({ request }: Route.LoaderArgs) { |
| 9 | const site = new URL(request.url).origin; |
| 10 | return new Response(securityTxt(new Date(), site), { |
| 11 | headers: { |
| 12 | "content-type": "text/plain; charset=utf-8", |
| 13 | "cache-control": "public, max-age=86400", |
| 14 | }, |
| 15 | }); |
| 16 | } |