digitalocean / digitalocean/nginxconfig.io
Per host security headers
- Dominant language
- JavaScript
- Stars
- 28.3k
- Forks
- 2k
- PR merge metrics
- No merged PRs in 30d
Description
## Feature request
### Feature description
I'd like to have Content-Security-Policy header different for different domains.
### How the feature is useful
If I have one domain running WordPress, which requires `unsafe-eval`, I want it only on this domain, not on others.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. Start by locating the NGINX configuration-generation path and establish how per-domain Content-Security-Policy settings should be specified; done means different domains can receive different policies, including domain-specific unsafe-eval, without changing other domains.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100