Package release
ocyan-plugin-security
mandel/stable ยท Version 0.1.1
MandelBlog server-side CSP and Django security policy integration
Metadata
| author | MandelBlog |
|---|---|
| classifiers |
|
| description_content_type | text/markdown |
| license_expression | LicenseRef-Proprietary |
| metadata_version | 2.4 |
| requires_dist |
|
| requires_python | <3.13,>=3.12 |
Release files
| File | Test results | History |
|---|---|---|
ocyan_plugin_security-0.1.1-py3-none-any.whl
|
|
|
ocyan_plugin_security-0.1.1.tar.gz
|
|
ocyan.plugin.security
ocyan.plugin.security is MandelBlogStack's server-side CSP and Django
security-header integration. It owns the reusable default CSP contribution,
HSTS defaults and nonce-node extension for Ocyan hosts. It does not own a
project's external service allow-list, reverse-proxy TLS configuration,
authentication policy, templates, or client-specific security exceptions.
The package remains compatible with the certified Ocyan core CSP aggregation contract and django-csp 3.8. A django-csp 4 migration is a coordinated core and consumer change, not a package-local substitution.
The default policy now protects admin and management paths too, does not permit
unsafe-inline styles, permits only self/data image sources, and permits Google
Fonts stylesheet and font-file hosts solely for the inherited Ocyan font
contract. A host that needs a different source must establish it through a
separately reviewed deployment/consumer policy; this plugin must not be forked
for a client exception.
Security credentials, report collectors, production headers and live browser policy checks are deployment responsibilities. Tests are deterministic and do not contact external services.