{"_id":"content-security-policy","_rev":"19-253c964489d6c537c20ef9324cf7b262","name":"content-security-policy","dist-tags":{"latest":"0.5.0"},"versions":{"0.1.0":{"name":"content-security-policy","version":"0.1.0","keywords":["express","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"license":"MIT","_id":"content-security-policy@0.1.0","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"0b313917f9bd000a49a767629165f79df49a71fc","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.1.0.tgz","integrity":"sha512-GeRDavffqkr7kKfG7gOnYjmhVxuPb/3FnkYCY6USfk9MypkpxxageJXM9BM1nir/cielg/1euoSYuVMxug5o6g==","signatures":[{"sig":"MEQCIHoKY9I8PmDSGjG+jRoJIAHUQME4CgEOQuztG/zoZcSEAiBbN8SjZpO4YJiAmHlF575FPIFYqXJiXB2C29kfhODfjw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"./lib","_from":"./","engines":{"node":">= 0.4.0"},"scripts":{"test":"mocha -u tdd"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git@github.com:samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"1.2.32","description":"Middleware to add Content-Security-Policy header.","directories":{"test":"test"},"dependencies":{},"devDependencies":{"mocha":"1.13.x"}},"0.1.1":{"name":"content-security-policy","version":"0.1.1","keywords":["express","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"license":"MIT","_id":"content-security-policy@0.1.1","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"0e31406d13b50715e935d21a7192959fbdb0fc01","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.1.1.tgz","integrity":"sha512-aArNwJbxJyMjvQ9yAHVGzsJy/OJl8UmL0NrPpw6D+J4uaMBvWV82fL4Tv316UJJBqN+4AD+vdH0M1+BSsXdpSg==","signatures":[{"sig":"MEUCIH9pDFhTcWDBzCQ90MQIsy+1TKkv4Hy8fg9/mKmIBkRuAiEAsjWxk6d9/+PjE/ZxRankT04vqk22FfBli4zZrqT4vdY=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"./lib","_from":"./","engines":{"node":">= 0.4.0"},"scripts":{"test":"mocha -u tdd"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git@github.com:samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"1.2.32","description":"Middleware to add Content-Security-Policy header.","directories":{"test":"test"},"dependencies":{},"devDependencies":{"mocha":"1.13.x"}},"0.2.0":{"name":"content-security-policy","version":"0.2.0","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.2.0","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"bfdf2e54d797387339c759d06b3014cd1e2a7670","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.2.0.tgz","integrity":"sha512-tbdKOMjU3tsrM3uEV8ebzMjj7QwxxYekfDW64fW8WIeKRkpk10uZj8yvXHcxNvtGge/gFUOeLmRvMGFGz/qOCQ==","signatures":[{"sig":"MEYCIQCEu4mTLw6Gznx9vn1B75mwODc7a+DgheBB3GRjZoAqLAIhAJbG20xx6EeG9xJy4gtKYr0/xbig/oTG6RZILcS1FJ4T","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"./lib","_from":"./","engines":{"node":">= 0.4.0"},"scripts":{"test":"mocha -u tdd"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git@github.com:samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"1.2.32","description":"Middleware to add Content-Security-Policy header.","directories":{},"dependencies":{},"devDependencies":{"mocha":"1.13.x"}},"0.2.2":{"name":"content-security-policy","version":"0.2.2","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.2.2","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"d0f42a88a6e2e114ea1eb8832aab72ec08957dd1","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.2.2.tgz","integrity":"sha512-rgE91nQkSkXx+tgL9DkTvSNIq2v00pWqy7EdE4cmU6r6zETM68jEO6HnL1extuDnXqi66a369PYTYtlOfqDysw==","signatures":[{"sig":"MEUCIByCJCmp0snmqoXd2jZ8zCUWGtaNDwjdUx9e0WyyUvloAiEA12T4fu49Um0+K6Ui9ufGhgiMO2VetsGU+na/StbEFxc=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"./lib","_from":".","_shasum":"d0f42a88a6e2e114ea1eb8832aab72ec08957dd1","engines":{"node":">= 0.4.0"},"gitHead":"4fdc00bbdfd6525190658047482eaf92d91ced2d","scripts":{"test":"mocha -u tdd"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"3.10.9","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"7.2.0","dependencies":{},"devDependencies":{"mocha":"1.13.x"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy-0.2.2.tgz_1485551866515_0.6119218857493252","host":"packages-12-west.internal.npmjs.com"}},"0.3.0":{"name":"content-security-policy","version":"0.3.0","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.3.0","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"7610a7c2175bb3339cc088b2961dbb40135a9aa4","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.3.0.tgz","integrity":"sha512-g6ziCnCGwEcWXmSxlbrJPt7m4AZQNGmBLS97/JOSwmEkzqJ9ybiGDZOPR3BPGiOyXcrsVmovj5w334tanvPY+Q==","signatures":[{"sig":"MEUCIHw9Fbpiq4YHovGF9pPN07bmxLBs/AE8c9zNLSDkhQLBAiEAmQ+fvGrpZLSsDPz2v63n8T631etJQEtmOgNQUr6L7OQ=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"./lib","_from":".","_shasum":"7610a7c2175bb3339cc088b2961dbb40135a9aa4","engines":{"node":">= 0.4.0"},"gitHead":"5129e16a82d970723ae22b02a6ab770c8de398f0","scripts":{"test":"mocha -u tdd"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"3.10.9","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"7.2.0","dependencies":{},"devDependencies":{"mocha":"1.13.x"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy-0.3.0.tgz_1485553408018_0.7206620587967336","host":"packages-12-west.internal.npmjs.com"}},"0.3.1":{"name":"content-security-policy","version":"0.3.1","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.3.1","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"185811260075cfa33624617ffeb526309bba5009","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.3.1.tgz","integrity":"sha512-ONyBz9kUeuhpT1HpbIjhe9z3821smn50T5cwz9J8G7HSXTc+67Vn/nyvXV2lDz4AygTrgUmlP9aGKThKeJeOwA==","signatures":[{"sig":"MEUCIBv/gDdUoyQLMdqbufDSAD+UukPVd83hZYPddGMSh5sVAiEA5398nz0mVi9a5czw9KdWpFoEn1B67kis/e4vXyRF410=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"lib/index.js","_from":".","_shasum":"185811260075cfa33624617ffeb526309bba5009","engines":{"node":">= 0.4.0"},"gitHead":"f2c1ebff21828a8f3d59460b57f47201ab52c773","scripts":{"dev":"npm-run-all -p --silent watch live","live":"live-server -q --port=4003 --ignorePattern='(js|css|png)$' coverage","test":"ava test","clean":"rm -rf coverage/ .nyc_output/","watch":"watch 'npm run coveragehtml' test lib","pretest":"semistandard","coverage":"nyc npm test","coveralls":"nyc report --reporter=text-lcov | coveralls","coveragehtml":"nyc report -r html","precoveragehtml":"npm run coverage"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"3.10.9","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"7.2.0","dependencies":{},"devDependencies":{"ava":"*","nyc":"*","watch":"*","live-server":"*","npm-run-all":"*","semistandard":"*"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy-0.3.1.tgz_1511471897327_0.2509597991593182","host":"s3://npm-registry-packages"}},"0.3.2":{"name":"content-security-policy","version":"0.3.2","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.3.2","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"bfe2238c23b231fdc04d684dbccc363df68860c1","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.3.2.tgz","integrity":"sha512-PcpOdQ3lCkaS0Jj3TwTOosvigg50JV4dpL05IViYKTYXV+dr0t6jjsq8fCacLM6yQ+Hjc+lMSXYasdIGM09XtA==","signatures":[{"sig":"MEQCIFQmAXlLdjeNR5+PQKVNtHfmwbfiaTaOgZpRevDa0GcxAiA586UjpI3gKhOio1D3RgzkSvQYLmeerrbotPQUbIvxSg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}]},"main":"lib/index.js","_from":".","_shasum":"bfe2238c23b231fdc04d684dbccc363df68860c1","engines":{"node":">= 0.4.0"},"gitHead":"a5df2b997fa518b1072f478ac96476ef3ce74ef4","scripts":{"dev":"npm-run-all -p --silent watch live","live":"live-server -q --port=4003 --ignorePattern='(js|css|png)$' coverage","test":"ava test","clean":"rm -rf coverage/ .nyc_output/","watch":"watch 'npm run coveragehtml' test lib","pretest":"semistandard","coverage":"nyc npm test","coveralls":"nyc report --reporter=text-lcov | coveralls","coveragehtml":"nyc report -r html","precoveragehtml":"npm run coverage"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"3.10.9","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"7.2.0","dependencies":{},"devDependencies":{"ava":"*","nyc":"*","watch":"*","live-server":"*","npm-run-all":"*","semistandard":"*"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy-0.3.2.tgz_1511474669875_0.13074889313429594","host":"s3://npm-registry-packages"}},"0.3.3":{"name":"content-security-policy","version":"0.3.3","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.3.3","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"5228ff2c464b33df8d0ab3bf927ad356d628f707","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.3.3.tgz","fileCount":10,"integrity":"sha512-rvBgxpNmDrzNoISY0o0SaGqveW6Gr3+nkcrF5DEzWnG0wqfAZvCk1doSX9Pvyjzve/1XNxsMzZomlfwB+D64GA==","signatures":[{"sig":"MEQCIG5R9pxwAPfsXDqjSXkUvX+MXie+PhSsGv/quEyV9erBAiBHkyqQ5jZ4+N4DtsxOc8eLc+ZuJtMpHLLLckznYm5OUg==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":15161,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbH+1aCRA9TVsSAnZWagAAqXQP/RDz3RVHdqxBf+y6nglo\ntM5smBYrbn6Ka3EKbwOutoeSaObF1QDLOjqP+4iTH8o+U80L4O/wwwaQj5Pf\nARwChw47nHO8cl8mO1Wcs26m9anYpQkfDqyIokr9zQDvmoOJTJ70fye8/8rC\nWAFlBM2Elp6opZASNX1N5wbHqioofgO1dbByWTw9a5BrRWio4DkaBvDw/Zx1\n7MIL0xLKjMDcBoRkWF4G/9pzqpbXqsQIpZOrjyCelhspw3GKJL7RKrgacbzX\nyviK+cx9fAOTxydPYhPf5KSUE8+9Mqaq7rnIzzExxyepwl3eTuADsds+5/yP\nOc76E74LRZypD3xxyKxqEgKmKNkxFtN3SwvJUdLjGU0LY0lsBVlNJz6ywIvJ\nsIWwXv64vRjLbTjqDL27XrY355z9U7N2J7X+mJ/B/CYyIhqE9yJHssTBlh1h\npAQLFzBEUmjUsbXD8j0o+OIq8oybajR0u/Dd6eMnBzptowXxQH6Y8ZNQLWzb\nYmwj/dsF5cD7iDXgtdRkpTqcVmkT7MdoYsXIsBWzxUNTxCy0Ci5/xBcMN3JE\nsrFaiqXDLbA6IvxY6N5QD/nVScwqrvNNhFlQTW0CmyADK3nZo3syTbHxZCim\n64Sw5EAo+JSrbob28M7FJPDKs98EjJY1hcVCOWkloGrmjZ654W+2QM31TLZk\ny07t\r\n=BL3F\r\n-----END PGP SIGNATURE-----\r\n"},"main":"lib/index.js","engines":{"node":">= 0.4.0"},"gitHead":"762a20e07a3b36b4ada5973b40a32278fcf9032b","scripts":{"dev":"npm-run-all -p --silent watch live","live":"live-server -q --port=4003 --ignorePattern='(js|css|png)$' coverage","test":"ava test","clean":"rm -rf coverage/ .nyc_output/","watch":"watch 'npm run coveragehtml' test lib","pretest":"semistandard","coverage":"nyc npm test","coveralls":"nyc report --reporter=text-lcov | coveralls","coveragehtml":"nyc report -r html","precoveragehtml":"npm run coverage"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"5.6.0","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"9.11.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"ava":"*","nyc":"*","watch":"*","live-server":"*","npm-run-all":"*","semistandard":"*"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy_0.3.3_1528819033111_0.9141045323244723","host":"s3://npm-registry-packages"}},"0.3.4":{"name":"content-security-policy","version":"0.3.4","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"_id":"content-security-policy@0.3.4","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/samuelerdtman/content-security-policy#readme","bugs":{"url":"https://github.com/samuelerdtman/content-security-policy/issues"},"dist":{"shasum":"4fd8b8c8487ee24f886cdacbdc168742557ba99d","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.3.4.tgz","fileCount":15,"integrity":"sha512-phs2wrE6w0M93NRe0UavgeMfqDJttgfGCGMKF4h8PF4HAb5e72BltgXctn1DPI3lBgMgtlN7gJ5GOAa/bmBVFQ==","signatures":[{"sig":"MEYCIQDgLuT7qRHP8QHRsn+FZi0clvT/zHi7eA4g6deRagraTwIhALGthQIVbEwqz/zN7dBdSYuPptCyFMrZMu4vXIyT//uW","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":17745,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfM9KDCRA9TVsSAnZWagAAsQEP/3HmelLNTP3WjLPpLZuR\nak2l+ETKa8etqooRtuLzeHBEQ47+lc8Qf8NY08as9R4iaQqUBTfPHjOn1prR\nAGDgyfHqyopAHU/hupSBSB1dp+sBjN52EA67pF77ooB3NJgFKj/01jgQ4msw\nVfYgModkaG1xJpLOS7wq1Zd2pCCeEufUU7Y+aOTk2MEZHN69HPRJduHA73tO\nHb5MlHciB2TGWxiHy6Jn2A4hcr3iuUiox+iLqA/mPE1cD5brAnWMDQ7NBeOT\n+X5ktPSYEyQCKOuPU6jcvH2K0YS+l0nBpjglLzIXPcf5KyaPNK7ZaPWknaOT\n50ttuBbLQowkL+RCiSgzuGQSoa+B0ECHv8t60r9k8Fu5q3SivcbXCNnhdNbE\nKlQEUqd/fqtxCeXdHByb+4SpjInCnPvbUrwf7gEJaBGS/C8ulWPhLUQ//6IP\nO7HiFpwbbwwSNhDln7S1/sTq/xSgHycIL1JC1UjW106vSfgBQcu/UpddYDj0\n7cqeklirU+FmLjEYunqyP3TKe6aIbulpR8gRuLJyLF/iDVCNqu0S7YyNceiB\nntL5oEjau6vqgi5OHo7r1Q/yjYWLMlR52FFbhp7B3uFInTaWTKhoq9PVUBXt\n04vWvHiGuAa1mZk/6lSAUcRFjychOjhEJWpWAaEAkJMeDnSS8sHmY55S4V6p\nrEul\r\n=swzT\r\n-----END PGP SIGNATURE-----\r\n"},"main":"lib/index.js","engines":{"node":">= 0.4.0"},"gitHead":"cdfb858593a718bcf890a2cb2d9edc8ff77b2c42","scripts":{"dev":"npm-run-all -p --silent watch live","live":"live-server -q --port=4003 --ignorePattern='(js|css|png)$' coverage","test":"ava test/*.js","clean":"rm -rf coverage/ .nyc_output/","watch":"watch 'npm run coveragehtml' test lib","pretest":"semistandard --fix","coverage":"nyc npm test","coveralls":"nyc report --reporter=text-lcov | coveralls","coveragehtml":"nyc report -r html","precoveragehtml":"npm run coverage"},"_npmUser":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"licenses":[{"url":"http://www.opensource.org/licenses/MIT","type":"MIT"}],"repository":{"url":"git+ssh://git@github.com/samuelerdtman/content-security-policy.git","type":"git"},"_npmVersion":"6.14.4","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"12.16.2","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"ava":"*","nyc":"*","watch":"*","live-server":"*","npm-run-all":"*","semistandard":"*"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy_0.3.4_1597231747169_0.030654838849527355","host":"s3://npm-registry-packages"}},"0.4.0":{"name":"content-security-policy","version":"0.4.0","keywords":["express","connect","content-security-policy","security","csp"],"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"license":"MIT","_id":"content-security-policy@0.4.0","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"homepage":"https://github.com/erdtman/content-security-policy#readme","bugs":{"url":"https://github.com/erdtman/content-security-policy/issues"},"dist":{"shasum":"f83b87ccbe8e2bf53bf8e24eb44a1bec43363775","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.4.0.tgz","fileCount":5,"integrity":"sha512-pf5QebuWc+nJOEGCIl9JQLtZDo/f/qgulBtdU/QL0JmOQl5RmuWYuDXcFmrNnMFBP6EuDAjMzU1C1fr8+1GdwA==","signatures":[{"sig":"MEYCIQD6wl+hUWZ+GVfostfwHl2d4P5DwZtRs+JLOHj29rRi1AIhAIIfKO77x1PsrcEz5o3p6TCUkBNdrsSZgip2AFvMydek","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/content-security-policy@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":19296},"main":"lib/index.js","types":"lib/index.d.ts","engines":{"node":">=22"},"gitHead":"d8c9c787e78a0ec690761df133c50046ebcd1996","scripts":{"lint":"eslint","test":"node --test \"test/*.js\"","clean":"rm -rf coverage/","watch":"node --test --watch \"test/*.js\"","pretest":"npm run lint && npm run lint:types","coverage":"node --test --experimental-test-coverage --test-coverage-exclude=\"test/**\" --test-coverage-lines=100 --test-coverage-branches=100 --test-coverage-functions=100 \"test/*.js\"","lint:fix":"eslint --fix","lint:types":"tsc --noEmit","prepublishOnly":"npm run lint && npm run lint:types && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","approver":{"name":"samuelerdtman","email":"samuel@erdtman.se"},"trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3856f98-3051-40e9-8038-74197ce76c6b"}},"repository":{"url":"git+https://github.com/erdtman/content-security-policy.git","type":"git"},"_npmVersion":"12.0.2","description":"Middleware to add Content-Security-Policy header.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.10.0","@eslint/js":"^10.0.1","typescript":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/content-security-policy_0.4.0_1790106992991_0.013088658430284728","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"_id":"content-security-policy@0.5.0","bugs":{"url":"https://github.com/erdtman/content-security-policy/issues"},"dist":{"shasum":"c5f5c3624df562a9ee77b152304de8ac6470bb25","tarball":"https://registry.npmjs.org/content-security-policy/-/content-security-policy-0.5.0.tgz","integrity":"sha512-SMABJTPcHuPm7nCAtSpfbuUANoIcoPdjhMdveGjnDvSGI/a0kLZI9GFrX/v+DB47wKTZtZlzlXgpi+gxZ09Y9g==","fileCount":5,"unpackedSize":25975,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/content-security-policy@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDCTYoTvtZCTJlFy57ZCCPpOzoywpvkKu5+5AeXGjWfBQIhAIZ8YBCdW03yF0M54KNs95MnJFwapvtG+u/jk173OTgl"}]},"main":"lib/index.js","name":"content-security-policy","types":"lib/index.d.ts","author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"engines":{"node":">=22"},"gitHead":"8b17b0cba61847e6e3849dcd6199490fecb64c65","license":"MIT","scripts":{"lint":"eslint","test":"node --test \"test/*.js\"","clean":"rm -rf coverage/","watch":"node --test --watch \"test/*.js\"","pretest":"npm run lint && npm run lint:types","coverage":"node --test --experimental-test-coverage --test-coverage-exclude=\"test/**\" --test-coverage-lines=100 --test-coverage-branches=100 --test-coverage-functions=100 \"test/*.js\"","lint:fix":"eslint --fix","mutation":"npx --yes -p @stryker-mutator/core@9 -p typescript@5 stryker run","lint:types":"tsc --noEmit","prepublishOnly":"npm run lint && npm run lint:types && npm test"},"version":"0.5.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3856f98-3051-40e9-8038-74197ce76c6b"},"approver":{"name":"samuelerdtman","email":"samuel@erdtman.se"}},"homepage":"https://github.com/erdtman/content-security-policy#readme","keywords":["express","connect","content-security-policy","security","csp"],"repository":{"url":"git+https://github.com/erdtman/content-security-policy.git","type":"git"},"_npmVersion":"12.1.0","description":"Middleware to add Content-Security-Policy header.","directories":{},"maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"_nodeVersion":"22.23.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"devDependencies":{"eslint":"^10.10.0","@eslint/js":"^10.0.1","typescript":"^6.0.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/content-security-policy_0.5.0_1790365320849_0.3479741019508613"},"_hasShrinkwrap":false}},"time":{"created":"2014-01-16T23:30:47.132Z","modified":"2026-09-25T19:42:01.214Z","0.1.0":"2014-01-16T23:30:50.824Z","0.1.1":"2014-01-16T23:32:55.302Z","0.2.0":"2014-01-17T16:29:18.295Z","0.2.2":"2017-01-27T21:17:48.415Z","0.3.0":"2017-01-27T21:43:29.909Z","0.3.1":"2017-11-23T21:18:18.426Z","0.3.2":"2017-11-23T22:04:30.766Z","0.3.3":"2018-06-12T15:57:13.167Z","0.3.4":"2020-08-12T11:29:07.267Z","0.4.0":"2026-09-22T19:56:33.080Z","0.5.0":"2026-09-25T19:42:00.945Z"},"bugs":{"url":"https://github.com/erdtman/content-security-policy/issues"},"author":{"name":"Samuel Erdtman","email":"samuel@erdtman.se"},"license":"MIT","homepage":"https://github.com/erdtman/content-security-policy#readme","keywords":["express","connect","content-security-policy","security","csp"],"repository":{"url":"git+https://github.com/erdtman/content-security-policy.git","type":"git"},"description":"Middleware to add Content-Security-Policy header.","maintainers":[{"name":"samuelerdtman","email":"samuel@erdtman.se"}],"readme":"[![CI](https://github.com/erdtman/content-security-policy/actions/workflows/ci.yml/badge.svg)](https://github.com/erdtman/content-security-policy/actions/workflows/ci.yml)\n[![npm](https://img.shields.io/npm/v/content-security-policy.svg)](https://www.npmjs.com/package/content-security-policy)\n\n# content-security-policy\n\nConnect/Express middleware that adds a [Content-Security-Policy](https://www.w3.org/TR/CSP3/) header.\n\nNo runtime dependencies. Ships TypeScript declarations.\n\n## Install\n\n```sh\nnpm install content-security-policy\n```\n\n## Usage\n\n```js\nconst csp = require('content-security-policy');\nconst express = require('express');\nconst app = express();\n\nconst cspPolicy = {\n  'report-uri': '/reporting',\n  'default-src': csp.SRC_NONE,\n  'script-src': [csp.SRC_SELF, csp.SRC_DATA]\n};\n\nconst globalCSP = csp.getCSP(csp.STARTER_OPTIONS);\nconst localCSP = csp.getCSP(cspPolicy);\n\n// Applies to all requests that do not set a local policy.\napp.use(globalCSP);\n\napp.get('/', (req, res) => {\n  res.send('Using global content security policy!');\n});\n\n// Applies only to this path, overriding the global policy.\napp.get('/local', localCSP, (req, res) => {\n  res.send('Using path local content security policy!');\n});\n\napp.listen(3000, () => {\n  console.log('Example app listening on port 3000!');\n});\n```\n\n## Writing a policy\n\nA policy is a plain object keyed by directive name.\n\n| Value | Result |\n| --- | --- |\n| a string | `'script-src': \"'self'\"` → `script-src 'self'` |\n| an array of strings | `'script-src': [\"'self'\", 'https://cdn.example']` → `script-src 'self' https://cdn.example` |\n| `true` | `'upgrade-insecure-requests': true` → `upgrade-insecure-requests` |\n| falsy (`false`, `null`, `''`, `[]`) | the directive is omitted, which is handy for toggling one off |\n\nThe key `report-only` is not a directive. When truthy, the policy is sent as\n`Content-Security-Policy-Report-Only`, which reports violations without\nenforcing them:\n\n```js\napp.use(csp.getCSP({\n  'default-src': csp.SRC_NONE,\n  'report-uri': '/reporting',\n  'report-only': true\n}));\n```\n\nDirectives listed in `csp.DIRECTIVES` are emitted in specification order. Any\nother key is passed through verbatim after them, so a directive added to CSP\nafter this release can be used right away:\n\n```js\ncsp.getCSP({ 'default-src': csp.SRC_NONE, 'fenced-frame-src': 'https://ads.example' });\n// Content-Security-Policy: default-src 'none'; fenced-frame-src https://ads.example\n```\n\n### Validation\n\nThe policy is compiled once, when `getCSP` is called, and directive names and\nvalues are checked against the [CSP grammar](https://www.w3.org/TR/CSP3/#framework-directives)\nat that point. A malformed policy throws a `TypeError` at startup instead of\nproducing a broken header, or a 500, on every request:\n\n```js\ncsp.getCSP({ 'script-src': \"'self'\\r\\nX-Injected: yes\" });\n// TypeError: Invalid character \"\\r\" in Content-Security-Policy directive \"script-src\": ...\n```\n\nA directive name may contain only ASCII letters, digits and `-`. A value may\nnot contain control characters, `;`, `,` or non-ASCII characters — `;` and `,`\nseparate directives and policies, so a value containing one would inject\nanother directive or a second policy. A directive that is toggled off with a\nfalsy value is never validated, so switching one off cannot throw.\n\n### Constants\n\nSource expressions: `SRC_SELF`, `SRC_NONE`, `SRC_UNSAFE_INLINE`,\n`SRC_UNSAFE_EVAL`, `SRC_UNSAFE_HASHES`, `SRC_WASM_UNSAFE_EVAL`,\n`SRC_STRICT_DYNAMIC`, `SRC_REPORT_SAMPLE`, `SRC_DATA`, `SRC_BLOB`, `SRC_ANY`,\n`SRC_HTTPS`.\n\nSandbox tokens: `SANDBOX_ALLOW_FORMS`, `SANDBOX_ALLOW_SCRIPTS`,\n`SANDBOX_ALLOW_SAME`, `SANDBOX_ALLOW_TOP_NAVIGATION`,\n`SANDBOX_ALLOW_TOP_NAVIGATION_BY_USER_ACTIVATION`, `SANDBOX_ALLOW_DOWNLOADS`,\n`SANDBOX_ALLOW_MODALS`, `SANDBOX_ALLOW_POPUPS`,\n`SANDBOX_ALLOW_POPUPS_TO_ESCAPE_SANDBOX`, `SANDBOX_ALLOW_PRESENTATION`,\n`SANDBOX_ALLOW_POINTER_LOCK`, `SANDBOX_ALLOW_ORIENTATION_LOCK`.\n\nAlso `TRUSTED_TYPES_FOR_SCRIPT` for `require-trusted-types-for`.\n\n### STARTER_OPTIONS\n\n`csp.STARTER_OPTIONS` is a strict same-origin baseline: everything is denied by\ndefault, and scripts, styles, images, fonts, connections, frames and form posts\nare allowed from the same origin only. `object-src` and `base-uri` are locked\ndown because they are the usual ways to bypass an otherwise strict policy.\n\nTreat it as a starting point. Deploy it with `'report-only': true` first, watch\nthe reports, then widen it where your application genuinely needs it.\n\nIt is frozen, because it is shared by every consumer in the process. Spread it\nto derive a policy:\n\n```js\napp.use(csp.getCSP({\n  ...csp.STARTER_OPTIONS,\n  'script-src': [csp.SRC_SELF, 'https://cdn.example']\n}));\n```\n\n### Nonces\n\n`getCSP` compiles the policy once, when the middleware is created, so it cannot\nproduce a fresh nonce per request. If you need nonces, build the policy per\nrequest in your own middleware.\n\n## TypeScript\n\nDeclarations are bundled; no `@types` package is needed.\n\n```ts\nimport { getCSP, Policy, SRC_NONE, SRC_SELF } from 'content-security-policy';\n\nconst policy: Policy = {\n  'default-src': SRC_NONE,\n  'script-src': [SRC_SELF]\n};\n\napp.use(getCSP(policy));\n```\n\n## Requirements\n\nNode.js 22 or newer. The package is CommonJS and has no runtime dependencies.\n\n## Development\n\n```sh\nnpm install\nnpm test           # lint, typecheck and run the tests\nnpm run coverage   # tests with a coverage report (100% thresholds)\nnpm run watch      # re-run tests on change\nnpm run mutation   # mutation testing (slow, fetches Stryker on demand)\n```\n\n### How this is tested\n\nThe suite runs on `node:test` alone, with no test dependencies, and is layered\nso that each layer catches something the one above it cannot:\n\n| File | What it pins |\n| --- | --- |\n| `test/index.js` | What a policy compiles to, asserted as exact header strings, plus ordering, validation and the calls the middleware makes |\n| `test/http.js` | The same middleware against a real `http.ServerResponse` over a real socket — header serialisation, `next()`, and one policy overriding another |\n| `test/invariants.js` | Properties that must hold for every policy, over a few thousand generated ones, from a fixed seed |\n| `test/exports.js` | That the runtime exports and `lib/index.d.ts` describe the same API |\n| `test/docs.js` | That the examples in this README and in `examples/` still do what they claim |\n| `test/package.js` | The packed tarball: its contents, that `main` and `types` resolve, and that a TypeScript consumer can import it by name |\n| `test/types/usage.ts` | That valid usage compiles and invalid usage does not, via `@ts-expect-error` |\n\nLine coverage is held at 100%, but on a module this small that is easy and\nproves little, so suite strength is measured with mutation testing instead:\n`npm run mutation` changes the library and expects the tests to notice. It is\nheld at a 100% score, and runs weekly in CI rather than on every push. The few\nmutants that cannot be killed because they are behaviourally equivalent are\nmarked in `lib/index.js` with a `Stryker disable` comment and a reason.\n\nThe fuzz seed and case count can be overridden to reproduce or widen a run:\n\n```sh\nCSP_FUZZ_SEED=12345 CSP_FUZZ_RUNS=100000 node --test test/invariants.js\n```\n\n## Releases\n\nStaged from GitHub Actions on a `v*` tag push, with\n[npm provenance](https://docs.npmjs.com/generating-provenance-statements), so\neach release can be traced back to the commit and workflow run that built it.\nVerify with `npm audit signatures`. See [RELEASING.md](RELEASING.md).\n\n## License\n\nMIT\n","readmeFilename":"README.md"}