code-forge-io / code-forge-io/base-stack
Proposal: Add Optional Content-Security-Policy (CSP) Header Support
- 主要語言
- TypeScript
- 星號
- 366
- 分支
- 68
- PR 合併指標
- 30 天內沒有已合併 PR
描述
Hi @AlemTuzlak,
I’d like to contribute to the project by adding support for a default `Content-Security-Policy` (CSP) header — turned **off by default**, but easy to enable when needed.
**What I propose:**
* Add CSP header support with a sensible default policy (e.g., `default-src 'none'`)
* Make it **opt-in** via an env variable or config flag
Happy to follow your preferred coding style or integration pattern. Let me know if you’re open to this — I can start working on a pull request right away.
Thanks!
Duncan
貢獻指南
這個儲存庫沒有索引到貢獻指南
研究方向
No files, tests, or entry points are named in the issue. Before work starts, clarify the policy, configuration mechanism, affected request path, and acceptance tests; what counts as done cannot be determined from the current proposal.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- typescript
- 領域
- security
- Issue 類型
- 功能
- 難度
- 5/5
- 預估耗時
- 一週以上
- 活躍度
- 停滯
- 描述清晰度
- 需要釐清
- 新手友好度
- 25/100