Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CSP: document functions as directive values #404

Closed
EvanHahn opened this issue Mar 10, 2023 · 1 comment
Closed

CSP: document functions as directive values #404

EvanHahn opened this issue Mar 10, 2023 · 1 comment
Assignees

Comments

@EvanHahn
Copy link
Member

You can use functions as directive values in the contentSecurityPolicy middleware. See tests.

This is poorly-documented and we should add a note about it.

@EvanHahn EvanHahn self-assigned this Mar 26, 2023
webketje added a commit to webketje/helmet that referenced this issue Apr 24, 2024
- replaces HTML5Rocks URL with web.dev (redirect), add links to relevant MDN docs
- adds doc sections/ anchors for defaults, computed directives, disabling directives, and report only header
- clarifies that defaultSrc will default to 'self' (and is thus not required to the user) when useDefaults: true
- solves helmetjs#404, documents function signature and adds conditional CDN script-src loading example
- adds a common recipe to generate subresource-integrity hashes
- documents caveat of non-hostname values mentioned in helmetjs#454
@EvanHahn
Copy link
Member Author

EvanHahn commented Nov 3, 2024

This was done in 5ad717a, I believe.

@EvanHahn EvanHahn closed this as completed Nov 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant