code-forge-io / code-forge-io/base-stack
Proposal: Add Optional Content-Security-Policy (CSP) Header Support
未关闭
- 主要语言
- TypeScript
- 星标
- 366
- 派生
- 68
- PR 合并指标
- 30 天内没有已合并 PR
描述
Hi @AlemTuzlak,
I’d like to contribute to the project by adding support for a default `Content-Security-Policy` (CSP) header — turned **off by default**, but easy to enable when needed.
**What I propose:**
* Add CSP header support with a sensible default policy (e.g., `default-src 'none'`)
* Make it **opt-in** via an env variable or config flag
Happy to follow your preferred coding style or integration pattern. Let me know if you’re open to this — I can start working on a pull request right away.
Thanks!
Duncan
贡献指南
这个仓库没有索引到贡献指南
调研方向
Issue 中没有指定文件、测试或入口点。在开始工作之前,需要明确策略、配置机制、受影响的请求路径和验收测试;根据当前提案无法确定什么才算完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- typescript
- 领域
- security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100