mirror of
https://github.com/django/django.git
synced 2025-07-07 21:35:15 +00:00

This initial work adds a pair of settings to configure specific CSP directives for enforcing or reporting policy violations, a new `django.middleware.csp.ContentSecurityPolicyMiddleware` to apply the appropriate headers to responses, and a context processor to support CSP nonces in templates for safely inlining assets. Relevant documentation has been added for the 6.0 release notes, security overview, a new how-to page, and a dedicated reference section. Thanks to the multiple reviewers for their precise and valuable feedback. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>
9 lines
216 B
Python
9 lines
216 B
Python
from django.urls import path
|
|
|
|
from . import views
|
|
|
|
urlpatterns = [
|
|
path("request_attrs/", views.request_processor),
|
|
path("debug/", views.debug_processor),
|
|
path("csp_nonce/", views.csp_nonce_processor),
|
|
]
|