Package release

ocyan-plugin-security

mandel/testing ยท Version 0.1.1

MandelBlog server-side CSP and Django security policy integration

Metadata

author MandelBlog
classifiers
  • Framework :: Django
  • Programming Language :: Python :: 3 :: Only
  • Programming Language :: Python :: 3.12
  • Programming Language :: Python :: 3.13
description_content_type text/markdown
license_expression LicenseRef-Proprietary
requires_dist
  • Django<5.3,>=5.2
  • django-csp<4,>=3.8
  • ocyan.core<2,>=1.2.14
  • ocyan.main<3,>=2.0.2
requires_python <3.13,>=3.12

Release files

FileTest resultsHistory
ocyan_plugin_security-0.1.1-py3-none-any.whl
Size
5 KB
Type
Python Wheel
Python
3
ocyan_plugin_security-0.1.1.tar.gz
Size
4 KB
Type
Source

ocyan.plugin.security

ocyan.plugin.security is MandelBlogStack's server-side CSP and Django security-header integration. It owns the reusable default CSP contribution, HSTS defaults and nonce-node extension for Ocyan hosts. It does not own a project's external service allow-list, reverse-proxy TLS configuration, authentication policy, templates, or client-specific security exceptions.

The package remains compatible with the certified Ocyan core CSP aggregation contract and django-csp 3.8. A django-csp 4 migration is a coordinated core and consumer change, not a package-local substitution.

The default policy now protects admin and management paths too, does not permit unsafe-inline styles, permits only self/data image sources, and permits Google Fonts stylesheet and font-file hosts solely for the inherited Ocyan font contract. A host that needs a different source must establish it through a separately reviewed deployment/consumer policy; this plugin must not be forked for a client exception.

Security credentials, report collectors, production headers and live browser policy checks are deployment responsibilities. Tests are deterministic and do not contact external services.