Skip to content

Conversation

@maksimryndin
Copy link

Hey guys! thank you for the awesome framework!

There are cases when I want to change dynamically a CSP header (e.g. when inlining styles into the template).
To uphold CSP I need to render template with a nonce (or sha256) value.

The change to secure_headers middleware - when some secure header is already set by a controller, then the default one is not applied

@kaplanelad
Copy link
Contributor

kaplanelad commented Oct 19, 2025

thanks @maksimryndin.

Can you check the test that you added?

@maksimryndin
Copy link
Author

thanks @maksimryndin.

Can you check the test that you added?

Hey @kaplanelad ! Sorry for the long reply, I will check the test in some time (just overloaded with other things atm)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants