code-forge-io / code-forge-io/base-stack

Proposal: Add Optional Content-Security-Policy (CSP) Header Support

未關閉
#48 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
TypeScript
星號
366
分支
68
PR 合併指標
30 天內沒有已合併 PR

描述

Hi @AlemTuzlak,

I’d like to contribute to the project by adding support for a default `Content-Security-Policy` (CSP) header — turned **off by default**, but easy to enable when needed.

**What I propose:**

* Add CSP header support with a sensible default policy (e.g., `default-src 'none'`)
* Make it **opt-in** via an env variable or config flag

Happy to follow your preferred coding style or integration pattern. Let me know if you’re open to this — I can start working on a pull request right away.

Thanks!

Duncan

貢獻指南

這個儲存庫沒有索引到貢獻指南

研究方向

No files, tests, or entry points are named in the issue. Before work starts, clarify the policy, configuration mechanism, affected request path, and acceptance tests; what counts as done cannot be determined from the current proposal.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
typescript
領域
security
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
停滯
描述清晰度
需要釐清
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。