Skip to content

Add browser security hardening and unsafe content handling - #46

Merged
szeka9 merged 3 commits into
mainfrom
development
Aug 9, 2026
Merged

szeka9 merged 3 commits into
mainfrom
development

Conversation

@szeka9

@szeka9 szeka9 commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Add default safe CSP (Content Security Policy) headers to control resource loading and browser execution behavior.

Serve unsafe content types under /www/user_data as attachments, and prevent such resources being rendered by browsers.

Add missing content type mappings for common media types to improve browser interoperability.

Remove /lib/pyrobusta from the default configuration of served paths.

szeka9 added 3 commits August 2, 2026 21:53
Add default safe CSP (Content Security Policy) headers
to control resource loading and browser execution behavior.

Serve unsafe content types under /www/user_data as attachments,
and prevent such resources being rendered by browsers.

Add missing content type mappings for common media types to
improve browser interoperability.

Remove /lib/pyrobusta from the default configuration of
served paths.
Until now, 'http_auth_mode' controlled if CSRF protection
is enabled.  This commit assigns enabling and disabling browser
security headers to the same config key and renames it from
'http_auth_mode' to 'browser_security'. The type of the config
changes from string to boolean.
This change addresses issues found during static
analysis:

- hide methods for finalizing headers as it is not
meant to be used by user applications; this also
fixes a violation of max number of public methods

- update methods for applying patches, requiring
the class as an argument to avoid circular imports
in optional HTTP modules
@szeka9
szeka9 merged commit bf6b614 into main Aug 9, 2026
1 check passed
@szeka9
szeka9 deleted the development branch August 9, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant