Skip to content

Proposal: Add Optional Content-Security-Policy (CSP) Header Support #48

@duncanchen

Description

@duncanchen

Hi @AlemTuzlak,

I’d like to contribute to the project by adding support for a default Content-Security-Policy (CSP) header — turned off by default, but easy to enable when needed.

What I propose:

  • Add CSP header support with a sensible default policy (e.g., default-src 'none')
  • Make it opt-in via an env variable or config flag

Happy to follow your preferred coding style or integration pattern. Let me know if you’re open to this — I can start working on a pull request right away.

Thanks!

Duncan

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions