NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1925 most downloaded on PyPI
Django Content Security Policy support.
Last release 2 years ago
no release in 18 months
Ships unpredictably
gaps range from 2 weeks to 3.5 years
Most releases are documented
notes for 11 of 14 stable releases
Nothing withdrawn
no release was ever pulled
16 years old
23 releases · first in 2010
This release contains several breaking changes. For a complete migration guide, see: https://django-csp.readthedocs.io/en/latest/migration-guide.html
This release contains several breaking changes. For a complete migration guide, see:
https://django-csp.readthedocs.io/en/latest/migration-guide.html
Configuration Format: Moved to dict-based configuration which allows for setting policies for
both enforced and report-only. Instead of using individual settings with CSP_ prefixes, you now
use dictionaries called CONTENT_SECURITY_POLICY and/or CONTENT_SECURITY_POLICY_REPORT_ONLY.
(#219)
You can use Django's check command to automatically identify existing CSP settings and generate a
template for the new configuration format:
python manage.py check
This will detect your old CSP_ prefixed settings and output a draft of the new dict-based
configuration, giving you a starting point for migration.
Example:
Change from:
CSP_DEFAULT_SRC = ["'self'", "*.example.com"]
CSP_SCRIPT_SRC = ["'self'", "js.cdn.com/example/"]
CSP_IMG_SRC = ["'self'", "data:", "example.com"]
CSP_EXCLUDE_URL_PREFIXES = ["/admin"]to:
from csp.constants import SELF
CONTENT_SECURITY_POLICY = {
"DIRECTIVES": {
"default-src": [SELF, "*.example.com"],
"script-src": [SELF, "js.cdn.com/example/"],
"img-src": [SELF, "data:", "example.com"],
},
"EXCLUDE_URL_PREFIXES": ["/admin"],
}Nonce Configuration: Switched from specifying directives that should contain nonces as a
separate list to using a sentinel NONCE value in the directive itself.
(#223)
Example:
Change from:
CSP_INCLUDE_NONCE_IN = ['script-src', 'style-src']to:
from csp.constants import NONCE, SELF
CONTENT_SECURITY_POLICY = {
"DIRECTIVES": {
"script-src": [SELF, NONCE],
"style-src": [SELF, NONCE],
}
}Nonce Behavior: Changed how request.csp_nonce works - it is now Falsy
(bool(request.csp_nonce)) until it is read as a string (e.g., used in a template or with
str(request.csp_nonce)). Previously, it always tested as True, and testing generated the nonce.
(#270)
Before:
# The nonce was generated when this was evaluated
if request.csp_nonce:
# Do something with nonceAfter:
# This won't generate the nonce, and will evaluate to False until nonce is read as a string
if request.csp_nonce:
# This code won't run until nonce is used as a string
# To generate and use the nonce
nonce_value = str(request.csp_nonce)Dropped support for Django ≤3.2.
Dropped support for Python 3.8.
Dual Policy Support: Added support for enforced and report-only policies simultaneously using
the separate CONTENT_SECURITY_POLICY and CONTENT_SECURITY_POLICY_REPORT_ONLY settings.
Example:
from csp.constants import NONE, SELF
# Enforced policy
CONTENT_SECURITY_POLICY = {
"DIRECTIVES": {
"default-src": [SELF, "cdn.example.net"],
"frame-ancestors": [SELF],
},
}
# Report-only policy (stricter for testing)
CONTENT_SECURITY_POLICY_REPORT_ONLY = {
"DIRECTIVES": {
"default-src": [NONE],
"script-src": [SELF],
"style-src": [SELF],
"report-uri": "https://example.com/csp-report/",
},
}CSP Constants: Added CSP keyword constants in csp.constants (e.g., SELF instead of
"'self'") to minimize quoting mistakes and typos.
(#222)
Example:
Change from:
CSP_DEFAULT_SRC = ["'self'", "'none'"]to:
from csp.constants import SELF, NONE
CONTENT_SECURITY_POLICY = {
"DIRECTIVES": {
"default-src": [SELF, NONE], # No need to worry about quoting
}
}Added comprehensive type hints. (#228)
Added EXCLUDE_URL_PREFIXES check not a string. (#252)
Added support for CSP configuration as sets. (#251)
Changed REPORT_PERCENTAGE to be a float between 0.0 and 100.0 and improved behavior for 100%
report percentage to always send CSP reports.
Added ability to read the nonce after response if it was included in the header. This will raise
an error when nonce is accessed after response if not already generated.
(#269)
Made changes to simplify middleware logic and make CSPMiddleware easier to subclass. The updated
middleware returns a PolicyParts dataclass that can be modified before the policy is built.
(#237)
Full Changelog: 3.8...v4.0
One column per quarter.
Remove CSPMiddlewareAlwaysGenerateNonce by @robhudson in #274
CSPMiddlewareAlwaysGenerateNonce by @robhudson in #274Full Changelog: 4.0b6...4.0b7
CSPMiddlewareAlwaysGenerateNonce middleware that forced nonce headers when not used in
content encouraging better security practices (#274)Fix CSPMiddlewareAlwaysGenerateNonce by @jwhitlock in #272
Full Changelog: 4.0b5...4.0b6
CSPMiddlewareAlwaysGenerateNonce to always generate the nonce.
(#272)Allow reading nonce if it was included in header by @jwhitlock in #269
FalseLazyObject to CheckableLazyObject, use to wrap nonce by @jwhitlock in #270Full Changelog: 4.0b4...4.0b5
BACKWARDS INCOMPATIBLE change:
request.csp_nonce is now Falsy (bool(request.csp_nonce)) until it is read as a
string (for example, used in a template, or str(request.csp_nonce)). Previously,
it always tested as True, and testing generated the nonce.
(#270)Other changes:
Fix missing dependency on packaging by @titouanc in #266
Add Python 3.13, drop EOL Python 3.8 by @robhudson in #245
EXCLUDE_URL_PREFIXES check by @robhudson in #252Full Changelog: 4.0b2...4.0b3
EXCLUDE_URL_PREFIXES check (#252)Add missing report-only from csp replace example by @jamesbeith in #233
Full Changelog: 4.0b1...4.0b2
CSPMiddleware easier to subclass (#237)REPORT_PERCENTAGE to allow floats (e.g. for values < 1%) (#242)Restructure CSP Configuration with Streamlined Settings (backwards incompatible) by @robhudson in #219
Backwards-Incompatible Release - Beta for Community Testing
This release introduces significant changes that are not backwards compatible. We encourage all users to review the migration guide thoroughly before upgrading.
report_only to REPORT_ONLY in decorator docs by @robhudson in #224Full Changelog: 3.8...4.0b1
BACKWARDS INCOMPATIBLE changes:
NONCE in the directive itself.Other changes:
csp.constants, e.g. to replace "'self'" with SELFRemove deprecation warning for child-src by @rik in #154
Please note that 3.8 is Python-code-identical to 3.8rc1, and there were no regressions or problems noted or reported with 3.8rc0 nor 3.8rc1
django-csp lives!It's been more than a year since the last release and the project needed some refreshing before we can move forward with it.
This release aims to be functionally equivalent to 3.7, but with formal support for more modern Django and Python versions, all the way up to Django 5 on Python 3.12
Please see https://github.com/mozilla/django-csp/blob/3.8rc/CHANGES for a short summary of changes.
Feedback and bug reports are very welcome. 🙇
Full Changelog: 3.7...3.8
Please note: this release folds in a number of fixups, upgrades and documentation tweaks, but is functionally the same as 3.7. New features will come with 3.9+
Note: identical other than release packaging to 3.8rc1
Remove deprecation warning for child-src by @rik in #154
Please note that 3.8rc1 is almost identical to 3.8rc0, and there were no regressions or problems noted with 3.8rc0
It's been more than a year since the last release and the project needed some refreshing before we can move forward with it.
This release aims to be functionally equivalent to 3.7, but with formal support for more modern Django and Python versions, all the way up to Django 5 on Python 3.12
Please see https://github.com/mozilla/django-csp/blob/3.8rc1/CHANGES for a short summary of changes.
Feedback and bug reports are very welcome.
Full Changelog: 3.7...3.8rc1
Remove deprecation warning for child-src by @rik in https://github.com/mozilla/django-csp/pull/154
It's been more than a year since the last release and the project needed some refreshing before we can move forward with it.
This release aims to be functionally equivalent to 3.7, but with formal support for more modern Django and Python versions, all the way up to Django 5 on Python 3.12
Please see https://github.com/mozilla/django-csp/blob/3.8rc/CHANGES for a short summary of changes.
Feedback and bug reports are very welcome.
Full Changelog: https://github.com/mozilla/django-csp/compare/3.7...3.8rc
Please note: this release folds in a number of fixups, upgrades and documentation tweaks, but is functionally the same as 3.7. New features will come with 3.9+
Use 128 bits base64 encoded for nonce
Add support/testing for Django 2.2 and 3.0
New RateLimitedCSPMiddleware middleware
Remove support for Django 1.6 and 1.7 as they're out of life
- Add support for Django 1.11 - Add support for Python 3.6
Add deprecation warning for child-src
Add support for Django 1.10 middlewares
Add support for Python 3 and PyPy
Please note that this is a big release that touches quite a few parts so please make sure you're testing thoroughly and report any issues to https://github.com/mozilla/django-csp/issues
Disable CSP on built-in error pages.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →