Metadata-Version: 2.4
Name: ocyan.plugin.security
Version: 0.1.1
Summary: MandelBlog server-side CSP and Django security policy integration
Author: MandelBlog
License-Expression: LicenseRef-Proprietary
Classifier: Framework :: Django
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Requires-Python: <3.13,>=3.12
Description-Content-Type: text/markdown
Requires-Dist: Django<5.3,>=5.2
Requires-Dist: django-csp<4,>=3.8
Requires-Dist: ocyan.core<2,>=1.2.14
Requires-Dist: ocyan.main<3,>=2.0.2

# `ocyan.plugin.security`

`ocyan.plugin.security` is MandelBlogStack's server-side CSP and Django
security-header integration. It owns the reusable default CSP contribution,
HSTS defaults and nonce-node extension for Ocyan hosts. It does not own a
project's external service allow-list, reverse-proxy TLS configuration,
authentication policy, templates, or client-specific security exceptions.

The package remains compatible with the certified Ocyan core CSP aggregation
contract and django-csp 3.8. A django-csp 4 migration is a coordinated core and
consumer change, not a package-local substitution.

The default policy now protects admin and management paths too, does not permit
`unsafe-inline` styles, permits only self/data image sources, and permits Google
Fonts stylesheet and font-file hosts solely for the inherited Ocyan font
contract. A host that needs a different source must establish it through a
separately reviewed deployment/consumer policy; this plugin must not be forked
for a client exception.

Security credentials, report collectors, production headers and live browser
policy checks are deployment responsibilities. Tests are deterministic and do
not contact external services.
