{"_id":"@astral/csp-header","_rev":"8-3213c598f0966e05e2833cf5743e0998","name":"@astral/csp-header","dist-tags":{"latest":"1.0.5"},"versions":{"0.1.0":{"name":"@astral/csp-header","version":"0.1.0","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@0.1.0","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"28ab415c81516950cc114580d7cfb943e33521e0","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-0.1.0.tgz","fileCount":79,"integrity":"sha512-gFOJ0R+EQ+T+R/inMxV1MWHKYEy4X/dvKCnm7LSFFQ4CXoC33IjaJZbpgikMk4mVgp9odkm/YQrnqAt3LJfUNA==","signatures":[{"sig":"MEYCIQDj1TAUSn1W2oMwIykZg1/NRiVlWxHjf9UHThBfOkq6sgIhAMnJOTc2vlFIbkNFrIU+oPzGRSh6P+mV/vLE0nplT2dx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61182},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"1f409374c4e2c76fb503d2e9b5a61965356d549a","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"typescript":"^6.0.3","@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_0.1.0_1780493315643_0.5538709223135949","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@astral/csp-header","version":"0.2.0","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@0.2.0","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"15e7f73f095a6aae48568856c44554bdd49dc622","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-0.2.0.tgz","fileCount":79,"integrity":"sha512-P5rKBPnIJrlYT+vr4kynUs0uVUJKnsKOBjXKPwMfVET7BrLOnNxuF86Zk48icwV2cNVgSAfD4Yt5OIuh4ojyMg==","signatures":[{"sig":"MEUCIQD6kIm0QWMly+Sqzdkht6Ay4Zlih88BWPgWzj4eW0Fe0wIgZRQ7mMoGjXmNUhjSdmtCnfHu1aHMRkhzPIXI5IF5hj8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61183},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"bc03a8e44bed86639fb84a543ce23dbe2097219c","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"typescript":"^6.0.3","@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_0.2.0_1780495910181_0.26123371619842284","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@astral/csp-header","version":"1.0.0","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@1.0.0","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"f4c9f7df15de6657daf0cf90fc83c0b5a089a7f6","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.0.tgz","fileCount":79,"integrity":"sha512-aSFt37Pl0DqSN7CHtw1tysgUlX/1QJZqQJssu93asntjf+X2dki0D8VtsJk0KYl/XY1N7rxZ+JuauXTGHqP3Ag==","signatures":[{"sig":"MEYCIQDGJBoVcb4iUj4/0vG2xFEvF1QbsceUsficU3e/+EIK8wIhAI8ScoNURd+TnxsV5c1U/GejRmeyhgxwCKV62p1GKvlm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64407},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"0466d4cf795afdc4d04d01df412aba85afe31cd3","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"typescript":"^6.0.3","@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_1.0.0_1780498465120_0.5079652627702353","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@astral/csp-header","version":"1.0.1","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@1.0.1","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"b024f95b0e292dc000ded39adfd02d2f32edfbe5","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.1.tgz","fileCount":79,"integrity":"sha512-ch8lXdoqRWX2fdwBGha8zLFJ+oQezQFX9LjZVvZBvNNt36T4mLnthPPkayrB+y9CfJJO7FOpSKpKN1B2VdNX4g==","signatures":[{"sig":"MEQCIBW9xpDI+qnAkw9HUPKmUCJCQrcxOW6th8U/O0VJQnrOAiAVR8n8pJGYCRteR9n2ws/E9V0NfQXdJR185BD73lGVOw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64654},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"3f687b1fc481f3cd2344b43abb5b7667ac5f29a4","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"typescript":"^6.0.3","@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_1.0.1_1780558257876_0.18034210445092147","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@astral/csp-header","version":"1.0.2","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@1.0.2","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"fea72672abc7f4795c2fb07c17d9db4defcc1695","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.2.tgz","fileCount":79,"integrity":"sha512-jXh+57kmqxjaKy1eMDScjxugKUFZEdpu6bZISEVoulRZdRH7X0/ZpyxP82utyj0Zwp8wL68IIPQ3pcCmFSzyCQ==","signatures":[{"sig":"MEUCIGDLLzwhyII23BZWwYs5i5RlBk53hpUlhWbMiqwioWf2AiEA/8d+Ws539qEX8LVvraPb5t7oyOPiIx9FxplbO6UjZCY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64626},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"9df68256cdb6d911a10dcbf6013e6b2c7b12277f","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_1.0.2_1780559469062_0.8692432757803401","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@astral/csp-header","version":"1.0.3","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@1.0.3","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"7c26153b2c33dd39354004f99996371c2877d27d","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.3.tgz","fileCount":79,"integrity":"sha512-L2FyyCf2dgVUrrhw5Jnbk1kU5Pv1funUq2sRfK+FKPERrJoLiP/1jpZFryUEy18GgH6A+e/iDsDfu89saACzjg==","signatures":[{"sig":"MEYCIQDYEuLhPJpb1l6T1Nlb6kE0pbaoBCxxkdlujXZwOZ7KygIhAJSGZhrIfBqkJo3tFZCsPiypt9+wQv//1Mh75RFlY5gg","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64629},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"393220af5de4fd65b402f26f862ac14764d909b5","_npmUser":{"name":"astral_frontend","email":"frontendastral@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_1.0.3_1780559585959_0.7796501754477427","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@astral/csp-header","version":"1.0.4","author":{"name":"Astral.Soft"},"license":"MIT","_id":"@astral/csp-header@1.0.4","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"dist":{"shasum":"a636a4a9544e4ace4655148926e6aaa05f7c3dd4","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.4.tgz","fileCount":95,"integrity":"sha512-jmnrLPs7zCj6QPoU9bLfNA6ykh2I2piWBgpO8rTbbPBR5VfsrootxvztJ+Q4QcEggOC7YbXFL91Kfo8BNvvabg==","signatures":[{"sig":"MEUCIBXY0Q97YuP9GsKQyFGI+1Np71nYgfTMSAELEnJANccpAiEAwC9WkMi13Ri5PRu90vvCsXTF38EJe+ek8qHdSzR3xro=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDCFMPM0fTtXjvNs1InfOFKwNeaC2Qz9bh7VLxspjDtwAiANvF0/Ayt6xu3U/DGDYaLSISGHsfxZz/HaBYcmloTHAA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":74695},"main":"./node/index.js","types":"./index.d.ts","module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"0f4f34e2b88c69d66ebd468ac8bfca983b187afd","_npmUser":{"name":"and_tem","email":"and.tem.dev@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"_nodeVersion":"26.1.0","dependencies":{"@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/csp-header_1.0.4_1789126421330_0.2889311377176649","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"_id":"@astral/csp-header@1.0.5","dist":{"shasum":"b52e53ec46b0c0839413a90c8e14c0b0b1bcde75","tarball":"https://registry.npmjs.org/@astral/csp-header/-/csp-header-1.0.5.tgz","fileCount":95,"integrity":"sha512-ri8R/mVHn3l6HoIFMapG2RX2pfhEIB+Nyy2YThXUVuKcJYlJ/ktAjPecQxHdlGtkdjVXy16A7V/Y6iycmaMRTA==","signatures":[{"sig":"MEYCIQCwS01qlD3z5SdT32RVyI0JIaLzwIajFmRpa0DpKPPzSQIhAPKa5aDvM8Zthw0IYWQhdigHniHKfZ+oDxibdoq4FLzs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFh3nrJRvBWc1IJvCALXjJ4z6Cq49ZLyjxBbYMMM9Sa6AiAl0nclnHi/+O53mrFGOKQko38y0hC9EIj6Fl0X40lCZQ=="}],"unpackedSize":75172},"main":"./node/index.js","name":"@astral/csp-header","types":"./index.d.ts","author":{"name":"Astral.Soft"},"module":"./index.js","engines":{"node":">=20"},"exports":{".":{"node":"./node/index.js","types":"./index.d.ts","import":"./index.js","module":"./index.js","default":"./index.js","require":"./node/index.js"}},"gitHead":"5c1fed2aad3b1d9fd39ce920492252120d03a277","license":"MIT","version":"1.0.5","_npmUser":{"name":"and_tem","email":"and.tem.dev@gmail.com"},"repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"_npmVersion":"11.13.0","description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","directories":{},"maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"_nodeVersion":"26.1.0","dependencies":{"@astral/validations":"^4.27.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/csp-header_1.0.5_1790948165595_0.6262442268887283"}}},"time":{"created":"2026-06-03T13:28:35.502Z","modified":"2026-10-02T13:36:05.859Z","0.1.0":"2026-06-03T13:28:35.804Z","0.2.0":"2026-06-03T14:11:50.310Z","1.0.0":"2026-06-03T14:54:25.280Z","1.0.1":"2026-06-04T07:30:58.013Z","1.0.2":"2026-06-04T07:51:09.243Z","1.0.3":"2026-06-04T07:53:06.120Z","1.0.4":"2026-09-11T11:33:41.443Z","1.0.5":"2026-10-02T13:36:05.682Z"},"author":{"name":"Astral.Soft"},"license":"MIT","repository":{"url":"https://git.astralnalog.ru/frontend.shared/csp-header","type":"git"},"description":"Библиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config. Позволяет централизованно обновлять набор доменов и политик для CSP.","maintainers":[{"name":"and_tem","email":"and.tem.dev@gmail.com"},{"name":"astral_frontend","email":"frontendastral@gmail.com"}],"readme":"# @astral/csp-header\n\nБиблиотека для генерации Content Security Policy (CSP) заголовков и их инжектирования в nginx config.\nПозволяет централизованно обновлять набор доменов и политик для CSP.\n\n## Основные возможности\n\n- Генерация CSP заголовков на основе набора инструкций.\n- Готовые наборы инструкций для сервисов, используемых в компании.\n- Инструменты для вставки заголовков в конфигурацию Nginx.\n\n## Базовое использование\n\n<!-- cSpell:disable -->\n```.deploy/nginx.conf```\n```\nhttp {\n  server {\n    location / {\n      alias /usr/share/nginx/html/;\n      index index.html;\n\n      add_header X-Frame-Options SAMEORIGIN;\n      add_header Content-Security-Policy \"Сгенерируется при билде c помощью .scripts/generateCsp\";\n    }\n  }\n}\n```\n\n```.scripts/generateCsp.mjs```\n```typescript\nimport path from 'node:path';\nimport {\n  astralFrontendStaticInstruction,\n  astralIdentityInstruction,\n  coreInstruction,\n  generateCsp,\n  injectToNginxConfig,\n  sentryInstruction,\n  uxFeedbackInstruction,\n  yandexMetrikaInstruction,\n} from '@astral/csp-header';\n\nconst csp = generateCsp({\n  instructions: [\n    coreInstruction,\n    astralFrontendStaticInstruction,\n    uxFeedbackInstruction,\n    yandexMetrikaInstruction,\n    sentryInstruction,\n    astralIdentityInstruction,\n  ],\n  // При возникновении блокировки ресурса CSP будет отправлен отчет в sentry\n  reportUrl:\n    'https://sentry.infra.yandex.astral-dev.ru/api/000/security/?sentry_key=123',\n});\n\ninjectToNginxConfig({\n  csp,\n  nginxConfigPath: path.resolve('.deploy', '.nginx', 'nginx.conf'),\n});\n```\n\n```.deploy/Dockerfile```\n```dockerfile\n# BUILD\nRUN npm run build\nRUN node ./.scripts/production/generateCSP.mjs\n\nFROM harbor.infra.yandex.astral-dev.ru/proxy-hub.docker.com/fholzer/nginx-brotli:v1.28.0\n\nCOPY --from=build /usr/src/app/apps/demo/.deploy/.nginx/nginx.conf /etc/nginx/nginx.conf\nCOPY --from=build /usr/src/app/apps/demo/dist /usr/share/nginx/html\n```\n<!-- cSpell:enable -->\n\n**[Пример в project-starter](https://git.astralnalog.ru/frontend.shared/project-starter/-/blob/master/apps/cold-start/.scripts/production/generateCSP.mjs?ref_type=heads)**\n\n## Готовые инструкции \n\n### `coreInstruction`\n\n#### Разрешено:\n- **Собственный домен (`self`):** Загрузка любого контента (скрипты, стили, картинки, шрифты), а также запросы (fetch/XHR) и WebSocket-соединения (ws/wss) ТОЛЬКО с текущим доменом.\n- **Скрипты:** Инлайн-скрипты (`<script>...</script>`) и динамический код через `eval()`.\n- **Стили:** Инлайн-стили (атрибуты `style=\"...\"` и теги `<style>`).\n- **Изображения:** Загрузка изображений со своего домена и через `data:` URI.\n- **Воркеры и фреймы:** Запуск Web Workers и загрузка фреймов (iframe) со своего домена + через `blob:` URL.\n- **Объекты:** Загрузка плагинов (например, `<object>`) только со своего домена.\n\n#### Запрещено:\n- **Встраивание текущего сайта в iframe:** Встраивать сайт в iframe разрешено только на текущем домене. Приоритетнее X-Frame-Options заголовка\n\nГенерируемое значение заголовка:\n```\ndefault-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self'; connect-src 'self'; worker-src 'self' blob:; frame-src 'self' blob:; frame-ancestors 'self'; child-src 'self' blob:; object-src 'self';\n```\n\n---\n\n### `yandexMetrikaInstruction`\n\nРазрешает загрузку скриптов счетчиков, отправку аналитики, сбор данных для Яндекс.Метрика через https и WebSocket.\nЛогирование кликов, локальные порты вебвизора и отображение во фреймах на доменах yandex.\nСодержит большой набор доменов, указанных [на сайте yandex](https://yandex.com/support/metrica/en/code/install-counter-csp#urls).\n\n---\n\n### `sentryInstruction`\n\nДобавляет разрешение на отправку запросов в `https://sentry.infra.yandex.astral-dev.ru/`.\n\n---\n\n### `googleRecaptchaInstruction`\n\nРазрешает скрипты капчи, фреймы проверки и статические изображения gstatic.\n\n---\n\n### `telegramInstruction`\n\nРазрешает загрузку аватарок пользователей, скрипты и сетевые запросы к доменам Telegram.\n\n---\n\n### `uxFeedbackInstruction`\n\nРазрешает скрипты, стили, шрифты Google Fonts, изображения и сетевые соединения для поддоменов `uxfeedback.ru`.\n\n---\n\n### `astralIdentityInstruction`\n\nРазрешает загрузку изображений/иконок и сетевые запросы для продакшн и dev/stage стендов identity.\n\n---\n\n### `astralFrontendStaticInstruction`\n\nРазрешает загрузку скриптов, стилей, картинок, шрифтов и работу Web Workers из `https://frontend-static.astral.ru/`.\n\n---\n\n### `cryptoPluginsInstruction`\n\nПоддержка плагинов для работы с ЭЦП (Рутокен, JaCarta).\nРазрешает загрузку локального скрипта JaCarta WebClient, API Рутокен и сетевое взаимодействие с локальным портом 24738.\n\n---\n\n### `dadataInstruction`\n\nРазрешает запросы для `https://suggestions.dadata.ru`.\n\n---\n\n### `googleFontsInstruction`\n\nРазрешает импорт стилей и шрифтов из Google Fonts и CDNJS.\n\n## Кастомные инструкции\n\n```typescript\nimport {\n  generateCsp,\n  yandexMetrikaInstruction,\n  CSP_VALUES,\n} from '@astral/csp-header';\n\nconst customCoreInstruction = {\n  'default-src': [CSP_VALUES.self],\n  'script-src': [\n    CSP_VALUES.self,\n    CSP_VALUES.unsafeInline,\n    CSP_VALUES.unsafeEval,\n  ],\n  'img-src': [CSP_VALUES.self, CSP_VALUES.data, CSP_VALUES.blob],\n  'object-src': [CSP_VALUES.none],\n};\n\nconst myApiInstruction = {\n  'script-src': ['https://myapi.ru'],\n};\n\nconst csp = generateCsp({\n  instructions: [\n    customCoreInstruction,\n    myApiInstruction,\n    yandexMetrikaInstruction,\n  ],\n});\n```\n\n## Расширение coreInstruction\n\n```typescript\nimport {\n  generateCsp,\n  coreInstruction,\n} from '@astral/csp-header';\n\nconst extendsCoreInstruction = {\n  // coreInstruction для img-src содержит: 'img-src': [CSP_VALUES.self, CSP_VALUES.data]\n  // Результирующий header будет содержать 'img-src': [CSP_VALUES.self, CSP_VALUES.data, CSP_VALUES.blob]\n  'img-src': [CSP_VALUES.blob],\n};\n\nconst csp = generateCsp({\n  instructions: [\n    coreInstruction,\n    extendsCoreInstruction,\n  ],\n});\n```\n\n## reportUrl. Получение уведомлений о блокировке ресурсов\n\nРекомендуется настраивать `reportUrl` для отправки сообщений в sentry.\nСообщения могут указывать на неправильно настроенный CSP.\n\n## Принцип работы\n\n### generateCsp\n\n`generateCsp` делает merge для всех `instructions` и удаляет дубли.\n\n## Настройки ingress\n\nЗаголовок со стандартным набором инструкций получается длинным — 4 КБ вместе с остальными заголовками ответа, вместо страницы браузер может получить ошибку 502. Для увеличения лимита используйте аннотацию:\n\n```yaml\nnginx.ingress.kubernetes.io/proxy-buffer-size: \"16k\"\n```\n\n## Интеграция если уже настроен CSP в nginx\n\nЕсли вы интегрируете пакет и у вас уже настроен CSP **обязательно сверьте ваш текущий заголовок и сгенерированный**.\n","readmeFilename":"README.md"}