. \server\config\express.js xssProtection false, 'development'! == env if:
if ('test' !== env && 'development' !== env) { // <- add development env here
console.log("using lusca");
app.use(lusca({
csrf: {
angular: true
},
xframe: 'SAMEORIGIN',
hsts: {
maxAge: 31536000, //1 year, in seconds
includeSubDomains: true,
preload: true
},
xssProtection: true // <- or change this to false
}));
}