{"_id":"csp-rspack-plugin","_rev":"3-699d68ad0f668175de8b9c6baa3f9434","name":"csp-rspack-plugin","dist-tags":{"latest":"0.0.3"},"versions":{"0.0.1":{"name":"csp-rspack-plugin","version":"0.0.1","keywords":["webpack","csp","sri","subresource","integrity","html-webpack-plugin","primereact"],"author":{"name":"Slack"},"license":"MIT","_id":"csp-rspack-plugin@0.0.1","maintainers":[{"name":"harpsealjs","email":"wly13201@sina.com"}],"contributors":[{"url":"http://melloware.com","name":"Melloware","email":"mellowaredev@gmail.com"}],"homepage":"https://github.com/rspack-contrib/csp-rspack-plugin","bugs":{"url":"https://github.com/rspack-contrib/csp-rspack-plugin/issues"},"dist":{"shasum":"1a659922dcf5480da83c363fe0ace5b5b34aa337","tarball":"https://registry.npmjs.org/csp-rspack-plugin/-/csp-rspack-plugin-0.0.1.tgz","fileCount":35,"integrity":"sha512-8KUq1QShjWnuJdGZ+EmUO0GQvD7rYlmGn7apYbE6l1rzw+8Snw7h8o3JWoyqz203rNW0o23DglvNoq302HMWsA==","signatures":[{"sig":"MEUCIGcYNsfwU/GhCA/MfialXh06/Q6x1tKZYTJ3FvVrUoo0AiEAwEP6WG4pgp4yEUT7ZE4P5UlYH4MrOgb4FRzfIh/0hqk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":144821},"main":"plugin.js","_from":"file:csp-rspack-plugin-0.0.1.tgz","types":"plugin.d.ts","scripts":{"jest":"jest --config=./jest.config.js","test":"npm run eslint && npm run jest","eslint":"eslint .","release":"node ./scripts/release.mjs","eslint:fix":"eslint . --fix","jest:watch":"jest --watch --verbose=false --config=./jest.config.js","jest:coverage":"npm run jest:coverage:clean && npm run jest:coverage:generate && npm run jest:coverage:upload","test:coverage":"npm run test && npm run jest:coverage","jest:coverage:clean":"rimraf  ./coverage","jest:coverage:upload":"npx codecov","jest:coverage:generate":"jest --coverage --config=./jest.config.js"},"_npmUser":{"name":"harpsealjs","email":"wly13201@sina.com"},"_resolved":"/private/var/folders/fq/28rrs_zx0ds641lvj_yc2jgh0000gn/T/9659214e30ebd90231201b6fc59b3ce2/csp-rspack-plugin-0.0.1.tgz","_integrity":"sha512-8KUq1QShjWnuJdGZ+EmUO0GQvD7rYlmGn7apYbE6l1rzw+8Snw7h8o3JWoyqz203rNW0o23DglvNoq302HMWsA==","repository":{"url":"git+ssh://git@github.com/rspack-contrib/csp-rspack-plugin.git","type":"git"},"_npmVersion":"10.7.0","description":"A plugin which, when combined with HtmlRspackPlugin, adds CSP tags to the HTML output","directories":{},"_nodeVersion":"18.20.4","dependencies":{"lodash":"^4.17.21","cheerio":"^1.0.0","webpack-inject-plugin":"^1.5.5"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.0.1","execa":"9.5.2","eslint":"^8.5.0","rimraf":"^5.0.5","semver":"7.7.1","codecov":"^3.8.1","fs-extra":"11.3.0","prettier":"^2.2.1","memory-fs":"^0.5.0","babel-jest":"^29.0.1","css-loader":"^6.5.1","@rspack/core":"1.3.9","html-webpack-plugin":"^5.0.0-alpha.15","eslint-plugin-import":"^2.22.1","eslint-config-prettier":"^9.0.0","eslint-plugin-prettier":"^4.0.0","@continuous-auth/client":"2.3.2","mini-css-extract-plugin":"^2.4.5","eslint-config-airbnb-base":"^15.0.0"},"peerDependencies":{"@rspack/core":"^1.3.9","html-webpack-plugin":"^4 || ^5"},"peerDependenciesMeta":{"html-webpack-plugin":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/csp-rspack-plugin_0.0.1_1746677485622_0.7568641106886091","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"csp-rspack-plugin","version":"0.0.2","keywords":["webpack","csp","sri","subresource","integrity","html-webpack-plugin","primereact"],"author":{"name":"Slack"},"license":"MIT","_id":"csp-rspack-plugin@0.0.2","maintainers":[{"name":"harpsealjs","email":"wly13201@sina.com"}],"contributors":[{"url":"http://melloware.com","name":"Melloware","email":"mellowaredev@gmail.com"}],"homepage":"https://github.com/rspack-contrib/csp-rspack-plugin","bugs":{"url":"https://github.com/rspack-contrib/csp-rspack-plugin/issues"},"dist":{"shasum":"48de697eaebe1c97f46a2640e39d3816e9662ffd","tarball":"https://registry.npmjs.org/csp-rspack-plugin/-/csp-rspack-plugin-0.0.2.tgz","fileCount":35,"integrity":"sha512-UusJuVQl2tZ8Ze8+ffoDsL9bkAagEtvT/CYE3xv8R0gzFwh44+oSxW9zWBZPMEbkMdaiUnV/1JTERdL8TdQi/g==","signatures":[{"sig":"MEUCIG3LvA1KAN7lqkz+YtUV9pLSMtR0GXBAhoRCVvs01hgQAiEAjI44E06pSt3HS8x2sgIHSK87nI80LEmm+arFdmChLA8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/csp-rspack-plugin@0.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":144821},"main":"plugin.js","_from":"file:csp-rspack-plugin-0.0.2.tgz","types":"plugin.d.ts","scripts":{"jest":"jest --config=./jest.config.js","test":"npm run eslint && npm run jest","eslint":"eslint .","release":"node ./scripts/release.mjs","eslint:fix":"eslint . --fix","jest:watch":"jest --watch --verbose=false --config=./jest.config.js","jest:coverage":"npm run jest:coverage:clean && npm run jest:coverage:generate && npm run jest:coverage:upload","test:coverage":"npm run test && npm run jest:coverage","jest:coverage:clean":"rimraf  ./coverage","jest:coverage:upload":"npx codecov","jest:coverage:generate":"jest --coverage --config=./jest.config.js"},"_npmUser":{"name":"harpsealjs","email":"wly13201@sina.com"},"_resolved":"/tmp/fe3be31194d4d994b27c64cb9214def6/csp-rspack-plugin-0.0.2.tgz","_integrity":"sha512-UusJuVQl2tZ8Ze8+ffoDsL9bkAagEtvT/CYE3xv8R0gzFwh44+oSxW9zWBZPMEbkMdaiUnV/1JTERdL8TdQi/g==","repository":{"url":"git+ssh://git@github.com/rspack-contrib/csp-rspack-plugin.git","type":"git"},"_npmVersion":"10.8.2","description":"A plugin which, when combined with HtmlRspackPlugin, adds CSP tags to the HTML output","directories":{},"_nodeVersion":"20.19.1","dependencies":{"lodash":"^4.17.21","cheerio":"^1.0.0","webpack-inject-plugin":"^1.5.5"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.0.1","execa":"9.5.2","eslint":"^8.5.0","rimraf":"^5.0.5","semver":"7.7.1","codecov":"^3.8.1","fs-extra":"11.3.0","prettier":"^2.2.1","memory-fs":"^0.5.0","babel-jest":"^29.0.1","css-loader":"^6.5.1","@rspack/core":"1.3.9","html-webpack-plugin":"^5.0.0-alpha.15","eslint-plugin-import":"^2.22.1","eslint-config-prettier":"^9.0.0","eslint-plugin-prettier":"^4.0.0","@continuous-auth/client":"2.3.2","mini-css-extract-plugin":"^2.4.5","eslint-config-airbnb-base":"^15.0.0"},"peerDependencies":{"@rspack/core":"^1.3.9","html-webpack-plugin":"^4 || ^5"},"peerDependenciesMeta":{"html-webpack-plugin":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/csp-rspack-plugin_0.0.2_1746677850172_0.9118625432696903","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"csp-rspack-plugin","version":"0.0.3","description":"A plugin which, when combined with HtmlRspackPlugin, adds CSP tags to the HTML output","main":"plugin.js","types":"plugin.d.ts","homepage":"https://github.com/rspack-contrib/csp-rspack-plugin","bugs":{"url":"https://github.com/rspack-contrib/csp-rspack-plugin/issues"},"repository":{"type":"git","url":"git+ssh://git@github.com/rspack-contrib/csp-rspack-plugin.git"},"keywords":["webpack","csp","sri","subresource","integrity","html-webpack-plugin","primereact"],"author":{"name":"Slack"},"contributors":[{"name":"Melloware","email":"mellowaredev@gmail.com","url":"http://melloware.com"}],"license":"MIT","dependencies":{"cheerio":"^1.0.0","lodash":"^4.17.21","webpack-inject-plugin":"^1.5.5"},"peerDependencies":{"@rspack/core":"^1.3.9","html-webpack-plugin":"^4 || ^5"},"peerDependenciesMeta":{"html-webpack-plugin":{"optional":true}},"devDependencies":{"@continuous-auth/client":"2.3.2","babel-jest":"^30.4.1","codecov":"^3.8.1","css-loader":"^6.5.1","eslint":"^8.5.0","eslint-config-airbnb-base":"^15.0.0","eslint-config-prettier":"^9.0.0","eslint-plugin-import":"^2.22.1","eslint-plugin-prettier":"^4.0.0","html-webpack-plugin":"^5.0.0-alpha.15","jest":"^30.4.2","memory-fs":"^0.5.0","mini-css-extract-plugin":"^2.4.5","prettier":"^2.2.1","rimraf":"^5.0.5","@rspack/core":"1.3.9","execa":"9.5.2","fs-extra":"11.3.0","semver":"7.7.1"},"scripts":{"eslint":"eslint .","eslint:fix":"eslint . --fix","jest":"NODE_OPTIONS=--experimental-vm-modules jest --config=./jest.config.js","test:real-content-hash":"node ./test-real-content-hash.mjs","jest:watch":"NODE_OPTIONS=--experimental-vm-modules jest --watch --verbose=false --config=./jest.config.js","jest:coverage:generate":"NODE_OPTIONS=--experimental-vm-modules jest --coverage --config=./jest.config.js","jest:coverage:clean":"rimraf  ./coverage","jest:coverage:upload":"npx codecov","jest:coverage":"npm run jest:coverage:clean && npm run jest:coverage:generate && npm run jest:coverage:upload","test":"npm run eslint && npm run jest && npm run test:real-content-hash","test:coverage":"npm run test && npm run jest:coverage","release":"node ./scripts/release.mjs"},"_id":"csp-rspack-plugin@0.0.3","_integrity":"sha512-Le9HQG61ZR4v+NBXocOYHds2zIEvrkqWoe6yXkiJozalYf+neHrpqNrkirt65HdHPIVaQC4lzkwJZZOg+VRURw==","_resolved":"/private/var/folders/pt/yfr1w15d6yj1tst04zv7_fxw0000gn/T/6c05dd876f418a8e755c2ecf11ead440/csp-rspack-plugin-0.0.3.tgz","_from":"file:csp-rspack-plugin-0.0.3.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-Le9HQG61ZR4v+NBXocOYHds2zIEvrkqWoe6yXkiJozalYf+neHrpqNrkirt65HdHPIVaQC4lzkwJZZOg+VRURw==","shasum":"1e5032c2b1c9dee635ea15d5cbfa8fac7e453b8a","tarball":"https://registry.npmjs.org/csp-rspack-plugin/-/csp-rspack-plugin-0.0.3.tgz","fileCount":40,"unpackedSize":178155,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDNqIt4x2I6le2bXMQB+0Dk2d6YY7BwISbvWe4fZGQPfAiBdtDk9K8BQMSL4WhLE6Z6mLpSXB+K7SqDaUpiLsp5Ocw=="}]},"_npmUser":{"name":"harpsealjs","email":"wly13201@sina.com"},"directories":{},"maintainers":[{"name":"harpsealjs","email":"wly13201@sina.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/csp-rspack-plugin_0.0.3_1785135828812_0.1502802931731051"},"_hasShrinkwrap":false}},"time":{"created":"2025-05-08T04:11:25.530Z","modified":"2026-07-27T07:03:49.102Z","0.0.1":"2025-05-08T04:11:25.803Z","0.0.2":"2025-05-08T04:17:30.516Z","0.0.3":"2026-07-27T07:03:48.950Z"},"bugs":{"url":"https://github.com/rspack-contrib/csp-rspack-plugin/issues"},"author":{"name":"Slack"},"license":"MIT","homepage":"https://github.com/rspack-contrib/csp-rspack-plugin","keywords":["webpack","csp","sri","subresource","integrity","html-webpack-plugin","primereact"],"repository":{"type":"git","url":"git+ssh://git@github.com/rspack-contrib/csp-rspack-plugin.git"},"description":"A plugin which, when combined with HtmlRspackPlugin, adds CSP tags to the HTML output","contributors":[{"name":"Melloware","email":"mellowaredev@gmail.com","url":"http://melloware.com"}],"maintainers":[{"name":"harpsealjs","email":"wly13201@sina.com"}],"readme":"# CSP Rspack Plugin\n\n> [!NOTE]  \n> This is a fork of [csp-webpack-plugin](https://github.com/melloware/csp-webpack-plugin), and will be used in Rspack to fix bugs and add some Rspack customized features.\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![npm version](https://badge.fury.io/js/csp-rspack-plugin.svg)](https://badge.fury.io/js/csp-rspack-plugin)\n![NPM Downloads](https://img.shields.io/npm/dm/csp-rspack-plugin?color=purple)\n[![Build Status](https://github.com/rspack-contrib/csp-rspack-plugin/actions/workflows/test.yml/badge.svg)](https://github.com/rspack-contrib/csp-rspack-plugin/actions/workflows/test.yml)\n\n## About\n\nThis plugin was forked from the wonderful work done by [Slack](https://github.com/slackhq/csp-html-webpack-plugin) but adds some key features:\n\n- [Subresource Integrity](http://www.w3.org/TR/SRI/) (SRI) is a security feature that enables browsers to verify that files they fetch are delivered without unexpected manipulation. Thanks to [webpack-subresource-integrity](https://www.npmjs.com/package/webpack-subresource-integrity) plugin.\n- [Trusted Types](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/trusted-types) support and use of [DOMPurify](https://www.npmjs.com/package/dompurify) to sanitize any `innerHTML` calls to prevent XSS\n- [PrimeReact](https://www.primefaces.org/primereact/) special handling for inline CSS styles. See [Issue #2423](https://github.com/primefaces/primereact/issues/2423)\n- Configure NONCE for pre-loaded scripts\n- Typescript definition\n- Default to SHA384 instead of SHA256\n- GitHub Actions Build and Dependabot to keep dependencies up to date\n\n## Description\n\nThis plugin will generate meta content for your [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy)\ntag and input the correct data into your HTML template, generated by [rspack.HtmlRspackPlugin](https://rspack.dev/plugins/rspack/html-rspack-plugin) or [html-webpack-plugin](https://github.com/jantimon/html-webpack-plugin/).\n\nAll inline JS and CSS will be hashed and inserted into the policy.\n\n## Installation\n\nInstall the plugin with npm:\n\n```shell\n$ npm i --save-dev csp-rspack-plugin\n```\n\n## Basic Usage\n\nInclude the following in your rspack config:\n\n```javascript\nconst { HtmlRspackPlugin } = require('@rspack/core');\nconst CspHtmlRspackPlugin = require('csp-rspack-plugin');\n\nmodule.exports = {\n  // rest of rspack config\n  plugins: [\n    new HtmlRspackPlugin()\n    new CspHtmlRspackPlugin({\n      // config here, see below\n    })\n  ]\n}\n```\n\nor you can use `html-webpack-plugin` instead:\n\n```javascript\nconst HtmlWebpackPlugin = require('html-webpack-plugin');\nconst CspHtmlRspackPlugin = require('csp-rspack-plugin');\n\nmodule.exports = {\n  // rest of webpack config\n\n  plugins: [\n    new HtmlWebpackPlugin()\n    new CspHtmlRspackPlugin({\n      // specific the path of html-webpack-plugin\n      htmlPlugin: require.resolve('html-webpack-plugin'),\n      // config here, see below\n    })\n  ]\n}\n```\n\n## Recommended Configuration\n\nBy default, the `csp-rspack-plugin` has a very lax policy. You should configure it for your needs.\n\nA good starting policy would be the following:\n\n```javascript\nnew CspHtmlRspackPlugin({\n  'script-src': '',\n  'style-src': ''\n});\n```\n\nAlthough we're configuring `script-src` and `style-src` to be blank, the CSP plugin will scan your HTML\ngenerated in `rspack.HtmlRspackPlugin` or `html-webpack-plugin` for external/inline script and style tags, and will add the appropriate\nhashes and nonces to your CSP policy. This configuration will also add a `base-uri` and `object-src` entry\nthat exist in the default policy:\n\n```xml\n<meta http-equiv=\"Content-Security-Policy\" content=\"\n  base-uri 'self';\n  object-src 'none';\n  script-src 'sha256-0Tumwf1AbPDHZO4kdvXUd4c5PiHwt55hre+RDxj9O3Q='\n             'nonce-hOlyTAhW5QI5p+rv9VUPZg==';\n  style-src 'sha256-zfLUTOi9wwJktpDIoBZQecK4DNIVxW8Tl0cadROvQgo='\n\">\n```\n\nThis configuration should work for most use cases, and will provide a strong layer of extra security.\n\n## Real content hash\n\nWhen the installed `@rspack/core` exposes\n`RealContentHashPlugin.getCompilationHooks`, generated inline script and style\nhashes are automatically updated after real content hash processing. This keeps\nthe CSP policy in sync when an inlined runtime contains asset content hashes\nthat Rspack changes later in the compilation.\n\nThis integration applies to generated hashes that remain embedded in the HTML.\nIf a custom `processFn` writes the policy only to an external file, such as an\nnginx header configuration, that callback is responsible for generating the\npolicy from final asset content.\n\n## All Configuration Options\n\n### `CspHtmlRspackPlugin`\n\nThis `CspHtmlRspackPlugin` accepts 2 params with the following structure:\n\n- `{object}` Policy (optional) - a flat object which defines your CSP policy. Valid keys and values can be found on the [MDN CSP](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy) page. Values can either be a string, or an array of strings.\n- `{object}` Additional Options (optional) - a flat object with the optional configuration options:\n  - `{string}` htmlPlugin - The path of html plugin, `HtmlRspackPlugin` by default which means using `rspack.HtmlRspackPlugin`\n  - `{boolean|Function}` enabled - if false, or the function returns false, the empty CSP tag will be stripped from the html output.\n    - The `htmlPluginData` is passed into the function as it's first param.\n    - If `enabled` is set the false, it will disable generating a CSP for all instances of `HtmlWebpackPlugin` in your webpack config.\n  - `{boolean}` integrityEnabled - Enable or disable SHA384  [Subresource Integrity](http://www.w3.org/TR/SRI/)\n  - `{boolean}` primeReactEnabled - Enable or disable custom [PrimeReact](https://www.primefaces.org/primereact/) NONCE value added to the environment for inline styles.\n  - `{boolean}` trustedTypesEnabled - Enable or disable [Trusted Types](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/trusted-types) handling which automatically adds DOMPurify to sanitize `innerHTML` calls to prevent XSS\n  - `{string}` hashingMethod - accepts 'sha256', 'sha384', 'sha512' - your node version must also accept this hashing method.\n  - `{object}` hashEnabled - a `<string, boolean>` entry for which policy rules are allowed to include hashes\n  - `{object}` nonceEnabled - a `<string, boolean>` entry for which policy rules are allowed to include nonces\n  - `{Function}` processFn - allows the developer to overwrite the default method of what happens to the CSP after it has been created\n    - Parameters are:\n      - `builtPolicy`: a `string` containing the completed policy;\n      - `htmlPluginData`: the `HtmlRspackPlugin` or `HtmlWebpackPlugin` `object`;\n      - `$`: the `cheerio` object of the html file currently being processed\n      - `compilation`: Internal rspack object to manipulate the build\n\n## Trusted Types\n\n[Trusted Types](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/trusted-types) is a newer CSP directive which adds XSS protection by preventing `innerHTML` without being trusted.\n\nTo add Trusted Type support automatically to your application you would add the `require-trusted-types-for 'script'` CSP directive.\n\n```javascript\n{\n  'base-uri': \"'self'\",\n  'object-src': \"'none'\",\n  'script-src': [\"'strict-dynamic'\"],\n  'style-src': [\"'self'\"],\n  'require-trusted-types-for': [\"'script'\"]\n};\n```\n\nIf `trustedTypesEnabled=true` this plugin will automatically add a special script which executes before any other script to enable a default policy that sanitizes HTML using DOMPurify.\n\n```javascript\nimport DOMPurify from 'dompurify';\n\nif (window.trustedTypes && window.trustedTypes.createPolicy) { // Feature testing\n    window.trustedTypes.createPolicy('default', {\n        createHTML: (string) => DOMPurify.sanitize(string, {RETURN_TRUSTED_TYPE: true}),\n        createScriptURL: string => sanitizeUrl(string),\n        createScript: string => string // allow scripts\n    });\n};\n```\n\nYou will need to include DOMPurify and Trusted Types Polyfill using `npm install dompurify trusted-types` to your `package.json`.\n\n\n## Appendix\n\n#### Default Policy:\n\n```javascript\n{\n  'base-uri': \"'self'\",\n  'object-src': \"'none'\",\n  'script-src': [\"'unsafe-inline'\", \"'self'\", \"'unsafe-eval'\"],\n  'style-src': [\"'unsafe-inline'\", \"'self'\", \"'unsafe-eval'\"]\n};\n```\n\n#### Default Additional Options:\n\n```javascript\n{\n  htmlPlugin: 'HtmlRspackPlugin',\n  enabled: true,\n  integrityEnabled: true,\n  primeReactEnabled: true,\n  trustedTypesEnabled: true,\n  hashingMethod: 'sha384',\n  hashEnabled: {\n    'script-src': true,\n    'style-src': true\n  },\n  nonceEnabled: {\n    'script-src': true,\n    'style-src': true\n  },\n  processFn: defaultProcessFn\n}\n```\n\n#### Full Default Configuration:\n\n```javascript\nnew CspHtmlRspackPlugin({\n  'base-uri': \"'self'\",\n  'object-src': \"'none'\",\n  'script-src': [\"'unsafe-inline'\", \"'self'\", \"'unsafe-eval'\"],\n  'style-src': [\"'unsafe-inline'\", \"'self'\", \"'unsafe-eval'\"]\n}, {\n  htmlPlugin: 'HtmlRspackPlugin',\n  enabled: true,\n  integrityEnabled: true,\n  primeReactEnabled: true,\n  trustedTypesEnabled: true,\n  hashingMethod: 'sha384',\n  hashEnabled: {\n    'script-src': true,\n    'style-src': true\n  },\n  nonceEnabled: {\n    'script-src': true,\n    'style-src': true\n  },\n  processFn: defaultProcessFn  // defined in the plugin itself\n})\n```\n## Advanced Usage\n### Generating a file containing the CSP directives\n\nSome specific directives require the CSP to be sent to the client via a response header (e.g. `report-uri` and `report-to`)\nYou can set your own `processFn` callback to make this happen.\n\n#### nginx\n\nIn your rspack config:\n\n```javascript\nconst { sources } = require('@rspack/core');\nconst { RawSource } = sources;\n\nfunction generateNginxHeaderFile(\n  builtPolicy,\n  _htmlPluginData,\n  _obj,\n  compilation\n) {\n  const header =\n    'add_header Content-Security-Policy \"' +\n    builtPolicy +\n    '; report-uri /csp-report/ \";';\n  compilation.emitAsset('nginx-csp-header.conf', new RawSource(header));\n}\n\nmodule.exports = {\n  {...},\n  plugins: [\n    new CspHtmlRspackPlugin(\n      {...}, {\n      processFn: generateNginxHeaderFile\n    })\n  ]\n};\n```\nIn your nginx config:\n```nginx\nlocation / {\n  ...\n  include /path/to/rspack/output/nginx-csp-header.conf\n}\n```\n\n## Publishing\n\nAdjust the version in the `package.json` if necessary, then\n\n```shell\nnpm login\n# This will run npm run build automatically\nnpm publish --access public\n```\n\nThen upload code to github, create tag & release.\n\n## Contribution\n\nContributions are most welcome! Please see the included contributing file for more information.\n\n## License\n\nThis project is licensed under MIT. Please see the included license file for more information.\n","readmeFilename":"README.md"}