Skip to content

Latest commit

 

History

History
30 lines (20 loc) · 1.01 KB

README.md

File metadata and controls

30 lines (20 loc) · 1.01 KB

CSP for Kirby

Adds a strict policy CSP header to Kirby projects.

General

Uses Kirby’s native nonce feature (used for the panel) to add a strict nonce-based content security policy header to all Kirby responses.

Installation

composer require kenshodigital/kirby-csp ^1.0

Usage

The plugin is not configurable and just follows the latest best practices.

However, scripts in your frontend are expected to include a nonce and the Kirby docs already provide a good example for this.

<script nonce="<?= $kirby->nonce() ?>"></script>