{"_id":"ember-cli-content-security-policy","_rev":"40-6ac5bc94f947d2cac829e541fd08cabb","name":"ember-cli-content-security-policy","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","dist-tags":{"latest":"2.0.3","next":"2.0.0-5"},"versions":{"0.1.0":{"name":"ember-cli-content-security-policy","version":"0.1.0","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"8ffc00156cd0eb053f42bf60834c150f0e79ce19","description":"This addon adds the `Content-Security-Policy` header to response sent from the Ember CLI Express server. Clearly, Ember CLI is not intended for production use, and neither is this addon. This is intended as a tool to ensure that CSP is kept in the forefro","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.1.0","_shasum":"892997a488f58c40fda9ec05e42a7b72302d81a4","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"892997a488f58c40fda9ec05e42a7b72302d81a4","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.1.0.tgz","integrity":"sha512-JnmjlkW2TnNmy8PZQaRQ9jRod8wQ49jpfbEGNJ5beIzrx16ABePf148cXsY7zGFLwPO5/BChdhED/jlkFTVJtg==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCPgfmr7+ANYhSvg/zp3/2NOYLltSRhEcdbu0sv5lp4tAIgKGs9LA/6LNpmAqUfBbdOT7M60+temSPtwya8fodR+CM="}]}},"0.1.1":{"name":"ember-cli-content-security-policy","version":"0.1.1","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"1bfd93c4411e3d62ee1baf706391858ea6539535","description":"This addon adds the `Content-Security-Policy` header to response sent from the Ember CLI Express server. Clearly, Ember CLI is not intended for production use, and neither is this addon. This is intended as a tool to ensure that CSP is kept in the forefro","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.1.1","_shasum":"54c7d8ce3fff5e2e82abe51bce304c281e184cc0","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"54c7d8ce3fff5e2e82abe51bce304c281e184cc0","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.1.1.tgz","integrity":"sha512-YxcKGP6n2I55kNURjqGTrvwxaHh5mblmzQoVDLIwHMZ7pWjLrBvOhJoyLb9r5mz8Sunrc+a2cVRVqLcFn0Vbzg==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDqiJ2EzH7nn88dqUfit8TlOqszmpQgbAQ0dHebMujs2AiAqIzLU4PVeIEp26Pz99cbU94eDUYeqy0+ocnWQ9TJWQA=="}]}},"0.1.2":{"name":"ember-cli-content-security-policy","version":"0.1.2","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"49b893c08a375180bdd730b6e61ec2a421f7c3a4","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.1.2","_shasum":"0b2f643c9d278a40499981e8666d1b3d3d03f7e7","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"0b2f643c9d278a40499981e8666d1b3d3d03f7e7","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.1.2.tgz","integrity":"sha512-6FOd9/8FUoZmUl8tpTcv9VC7VvEwLUNNxecJd23XA1hHmSclC7++/ATRrInNfymyT2m8iqxVSJJfQlz3NloAww==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD5/Ko9i99fkqrZZpkoc2XZuqRqS8ALYvu44naool44hgIgOYUvF2izYaELiTsZL8NjSk48V9qVMVIRUVMKcX5jMVI="}]}},"0.1.3":{"name":"ember-cli-content-security-policy","version":"0.1.3","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"d9c5fd5daf12fd45549eeaeec6e018da9232f2b0","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.1.3","_shasum":"7c76191f7902f344c6108dad18e2c1b5f07cf88e","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"7c76191f7902f344c6108dad18e2c1b5f07cf88e","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.1.3.tgz","integrity":"sha512-8JsFWJqMIwdG1TMmZkQShZEXt2+DZJyztCDJvd9aIFMkajxmHcsr5mp0UgTJGdnYt7Olh+AV2dDabct/N4yHTw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBSfH1toREMa8FHVC1CnaHA9qOGexsli6d/RUqvsn3wJAiEAiH/LggHSdDFcQSoiFV5hO7W2alBePOxnqvSuaL0Wx80="}]}},"0.1.4":{"name":"ember-cli-content-security-policy","version":"0.1.4","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"19f4707b9342a9b3f834336eb99b827c71114035","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.1.4","_shasum":"2cafda9d8ffcb4e7be70975dfdc4c80adcea5768","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"2cafda9d8ffcb4e7be70975dfdc4c80adcea5768","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.1.4.tgz","integrity":"sha512-ND+v+w9YYTMiU94qsdP8c9dEXmAMoCIBho1sW5CGKesyUJaZoD05BO8tConmNqOmnbWZ3YFdWhva5sAA/1wO8Q==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD3cQBylQ5JgBhTfAKVflAFX1sCOCKxHSs1C+o48O8mDQIhAIYc4Sk7hukQhuF8/BeN8+hXtA0GaDCmf264rYQIGeCm"}]}},"0.2.0":{"name":"ember-cli-content-security-policy","version":"0.2.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.1.1","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.0.46","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.0.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"fc5e02f5e8f101bf588687a5ac7f73bca5b81261","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.2.0","_shasum":"9c6f28e8055a0485ed23372c2ca201febf152f1f","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"9c6f28e8055a0485ed23372c2ca201febf152f1f","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.2.0.tgz","integrity":"sha512-cTuSytIqnYblQZj1RBa4Gpu15KgLNeBHAMBNriQWR+olLw0aSXidgSfLri17YXbrm57ehaRhCxOACKCXseJF2w==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGolIjSD3Fd1Uje1xhit5yp0GNWc2X+vxiwZSbjqibqNAiEA2rwl5k86H3Hcccy1qILXXwnllzEPdjcUK9/P0zPlctA="}]}},"0.2.1":{"name":"ember-cli-content-security-policy","version":"0.2.1","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.3.0","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.1.0","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.2.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"0bdab75728df086d43421f7d6a96239e8b1dc5ab","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.2.1","_shasum":"6f27133eb40b89b9589328b9b728e82e5887568a","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"6f27133eb40b89b9589328b9b728e82e5887568a","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.2.1.tgz","integrity":"sha512-jVasXCScpRzCgtN1WjwE9zk/jqD7gAhcyH7/jtGIDem3OwLhpFF/K3lH9uCiM32POhG4/augd0atiesqMzQySQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBu0KivTwNhux0phX3dVRgPwi1BbUe9O1lc13Xc0ez+rAiAy4H0LFiIMRuW8/tsu87Adw3YC65ZBWioNBRYmnGwOeA=="}]}},"0.3.0":{"name":"ember-cli-content-security-policy","version":"0.3.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","devDependencies":{"body-parser":"^1.2.0","broccoli-asset-rev":"0.3.0","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.1.0","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.2.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"e7372225228f7c596ce0490cbab3a06efa015646","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.3.0","_shasum":"c937f855db2f6fdd0e6daca4017d77e150c01f5d","_from":".","_npmVersion":"2.0.0-beta.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"c937f855db2f6fdd0e6daca4017d77e150c01f5d","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.3.0.tgz","integrity":"sha512-JcmGMOeB+z9bxXYu3EIfeWCusUWXABgnHMWFbYbx/P1jJnIiHKFul1++L/hJp5ao4cFhg+rCKV2BWAMIZLGMlg==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCPs/y4YfIqbDqRggKgtfnh8LMENqgx9OTqG4uIe7QHCwIgYehbyvtgFJrSDl8xjjrQdM6/x9xGvezvCkRXlS9HbAg="}]}},"0.4.0":{"name":"ember-cli-content-security-policy","version":"0.4.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"https://github.com/rwjblue/ember-cli-content-security-policy"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","dependencies":{"body-parser":"^1.2.0"},"devDependencies":{"broccoli-asset-rev":"0.3.0","broccoli-ember-hbs-template-compiler":"^1.6.1","ember-cli":"0.1.0","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.2.2","ember-cli-qunit":"0.1.0","ember-data":"1.0.0-beta.10","express":"^4.8.5","glob":"^4.0.5"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"bb9a5ce76fdb116806c209d192c8f08d384eeb24","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy","_id":"ember-cli-content-security-policy@0.4.0","_shasum":"71e4f228e68bcefc313f0ffae26f3600a0093276","_from":".","_npmVersion":"2.1.10","_nodeVersion":"0.10.33","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"71e4f228e68bcefc313f0ffae26f3600a0093276","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.4.0.tgz","integrity":"sha512-qd/wy6QbUW/jaCyT10PpHMpUyaW7gY4q8vG2IXYvAoeNiPAJbQnzp8FjGf9ZYptHH5sKQL0cBih1/qFrCuZBrA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGz+CS6ob6H1VT1eFPU1duMFGliYiibkrKkAj388xQKXAiAxxZuIedltTUWdw2WgkypsrhjeDxrWtY76w2bNdR6YjA=="}]}},"0.5.0":{"name":"ember-cli-content-security-policy","version":"0.5.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","dependencies":{"body-parser":"^1.12.3","chalk":"^1.0.0","ember-cli-babel":"^5.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.0.2","ember-cli":"0.2.3","ember-cli-app-version":"0.3.3","ember-cli-content-security-policy":"0.4.0","ember-cli-dependency-checker":"0.0.8","ember-cli-htmlbars":"0.7.4","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.3.0","ember-cli-qunit":"0.3.10","ember-cli-uglify":"1.0.1","ember-export-application-global":"^1.0.2","ember-disable-prototype-extensions":"^1.0.0","ember-try":"0.0.4"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","history-support-middleware","proxy-server-middleware"]},"gitHead":"b9589735c10f55a52dbf2849f7eaefc8aa052b6b","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@0.5.0","_shasum":"059ce3157bcdab65c29b1d26c31682410293f1c4","_from":".","_npmVersion":"3.5.0","_nodeVersion":"5.0.0","_npmUser":{"name":"rwjblue","email":"robert.w.jackson@me.com"},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"dist":{"shasum":"059ce3157bcdab65c29b1d26c31682410293f1c4","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.5.0.tgz","integrity":"sha512-a0dya5vkTkiJH+K/NNZtMf/EwVPXyotAAN4potyvjxp1dhfLKGTGq9BpVgfaj9jhr3ZoT3UPSb0daorZhKJkKQ==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBmqiXzQB9f5on/HB9kAR0Ut0/ZYlb+76JGf/sBVRgdsAiEA42lEChnWJfTbO6Uh3XdVk2SDCyMiN1jnl+lEUqzxKTo="}]}},"0.6.0":{"name":"ember-cli-content-security-policy","version":"0.6.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","dependencies":{"body-parser":"^1.12.3","chalk":"^1.0.0","ember-cli-babel":"^5.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.0.2","ember-cli":"0.2.3","ember-cli-app-version":"0.3.3","ember-cli-content-security-policy":"0.4.0","ember-cli-dependency-checker":"0.0.8","ember-cli-htmlbars":"0.7.4","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.3.0","ember-cli-qunit":"0.3.10","ember-cli-uglify":"1.0.1","ember-export-application-global":"^1.0.2","ember-disable-prototype-extensions":"^1.0.0","ember-try":"0.0.4"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"71e5a18f4230924e9e8df48e1d9bbc264f840cf7","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@0.6.0","_shasum":"5c8fb9f2a721574a296318ada01d1b5771d44411","_from":".","_npmVersion":"3.10.9","_nodeVersion":"7.1.0","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"shasum":"5c8fb9f2a721574a296318ada01d1b5771d44411","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.6.0.tgz","integrity":"sha512-bEEu+AhP+uur2qi2QL4asook+LfOlTdEsS1NOEjAWYCmJWcXI2vcrIbHQiCmI72fqqdgPh77tcukZ+iMj73qzw==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEmpmUcNEjJ7Epvj2Eb+oee4D2+kQklQ2hoYvxS17tfFAiBhV7/XRLvNlGe+Firqu6d3HaTC97aWKHUWcFLO4o4mBw=="}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"packages-12-west.internal.npmjs.com","tmp":"tmp/ember-cli-content-security-policy-0.6.0.tgz_1485871383574_0.5057116833049804"}},"0.6.1":{"name":"ember-cli-content-security-policy","version":"0.6.1","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","dependencies":{"body-parser":"^1.12.3","chalk":"^1.0.0","ember-cli-babel":"^5.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.0.2","ember-cli":"0.2.3","ember-cli-app-version":"0.3.3","ember-cli-content-security-policy":"0.4.0","ember-cli-dependency-checker":"0.0.8","ember-cli-htmlbars":"0.7.4","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.3.0","ember-cli-qunit":"0.3.10","ember-cli-uglify":"1.0.1","ember-export-application-global":"^1.0.2","ember-disable-prototype-extensions":"^1.0.0","ember-try":"0.0.4"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"124df40230173ccb8c0912f5eab8b283b135c90a","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@0.6.1","_shasum":"5040088f55213f5cf55839edc2d6039710c9577b","_from":".","_npmVersion":"3.10.9","_nodeVersion":"7.1.0","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"shasum":"5040088f55213f5cf55839edc2d6039710c9577b","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.6.1.tgz","integrity":"sha512-L6v/ngaOWu8b5UBn8JOrBp/3ZlpEyzT2ZxZIu2JBCe94RvQsE4ITwkmS79RgfnDSXQBHJS2TDt3n3sus6S4Q0w==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDtPWzv5MDgz3Yd4+Vyg1Rqp7DWpUhqBOcGvhEr+EuAGgIhALfgSGGU3wifxg9j4816GRLTZ5VIfHpcbV4XnPpcgyZv"}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"packages-18-east.internal.npmjs.com","tmp":"tmp/ember-cli-content-security-policy-0.6.1.tgz_1491233643029_0.4252235684543848"}},"0.6.2":{"name":"ember-cli-content-security-policy","version":"0.6.2","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","directories":{"doc":"doc","test":"tests"},"scripts":{"start":"ember server","build":"ember build","test":"ember test"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"engines":{"node":">= 0.10.0"},"author":"","license":"MIT","dependencies":{"body-parser":"^1.12.3","chalk":"^1.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.0.2","ember-cli":"0.2.3","ember-cli-babel":"^5.0.0","ember-cli-app-version":"0.3.3","ember-cli-content-security-policy":"0.4.0","ember-cli-dependency-checker":"0.0.8","ember-cli-htmlbars":"0.7.4","ember-cli-ic-ajax":"0.1.1","ember-cli-inject-live-reload":"^1.3.0","ember-cli-qunit":"0.3.10","ember-cli-uglify":"1.0.1","ember-export-application-global":"^1.0.2","ember-disable-prototype-extensions":"^1.0.0","ember-try":"0.0.4"},"keywords":["ember-addon"],"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"d8d817e2e154f4eeb1d7284582fc73f5d15e39a5","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@0.6.2","_npmVersion":"5.1.0","_nodeVersion":"8.1.2","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"integrity":"sha512-viNehfvb2ibERdQuZ+S5EwmNIDUZocFHzfYu4Z91kmu7Sd2ZgRUWDvoKok4+XGYqqtaUn/70UrYH4TQpp+Vbvw==","shasum":"15636998ce0dc224491b2a24f5d0e636a3f059a3","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-0.6.2.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDey9jPC1l7QweW70voygCOULfGRBIHurGywCe/q1lb/AiAizQXzu9QL/rrjEfqqyjEDbk+o6mzzUTKYXgeC4KSXhQ=="}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy-0.6.2.tgz_1501258860618_0.6133426479063928"}},"1.0.0":{"name":"ember-cli-content-security-policy","version":"1.0.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"scripts":{"build":"ember build","start":"ember server","test":"ember try:each"},"dependencies":{"body-parser":"^1.17.0","chalk":"^2.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.4.5","ember-ajax":"^3.0.0","ember-cli":"~2.14.2","ember-cli-babel":"^6.3.0","ember-cli-dependency-checker":"^1.3.0","ember-cli-eslint":"^3.0.0","ember-cli-htmlbars":"^2.0.1","ember-cli-htmlbars-inline-precompile":"^0.4.3","ember-cli-inject-live-reload":"^1.4.1","ember-cli-qunit":"^4.0.0","ember-cli-shims":"^1.1.0","ember-cli-sri":"^2.1.0","ember-cli-uglify":"^1.2.0","ember-disable-prototype-extensions":"^1.1.2","ember-export-application-global":"^2.0.0","ember-load-initializers":"^1.0.0","ember-resolver":"^4.0.0","ember-source":"~2.14.1","loader.js":"^4.2.3"},"engines":{"node":"^4.5 || 6.* || >= 7.*"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"e41c4804f87dcdb7d024e818150d939b23e66b61","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@1.0.0","_npmVersion":"5.3.0","_nodeVersion":"8.1.2","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"integrity":"sha512-5JSm22epRFkMH5h+/HgfnspjYPIXNP4RXUUSS8mj1KV3ZJZzcY3835YNnYYi3Tx5SLLHFqadT851zCXfcQei9w==","shasum":"4f7d72997d4209cd59f10d3b0070fdb39593ed2d","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-1.0.0.tgz","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD0YJkjIBocSvypifzro8afQP3I7uQGDUk2zyteiGumngIgFNekB7TnmXAGAgrPzYge04afUTr5LJ56T/G3w4j/iNY="}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy-1.0.0.tgz_1502805749523_0.24366505024954677"}},"1.1.0":{"name":"ember-cli-content-security-policy","version":"1.1.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"scripts":{"build":"ember build","start":"ember server","test":"ember try:each"},"dependencies":{"body-parser":"^1.17.0","chalk":"^2.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.4.5","ember-ajax":"^3.0.0","ember-cli":"~2.14.2","ember-cli-babel":"^6.3.0","ember-cli-dependency-checker":"^1.3.0","ember-cli-eslint":"^3.0.0","ember-cli-htmlbars":"^2.0.1","ember-cli-htmlbars-inline-precompile":"^0.4.3","ember-cli-inject-live-reload":"^1.4.1","ember-cli-qunit":"^4.0.0","ember-cli-shims":"^1.1.0","ember-cli-sri":"^2.1.0","ember-cli-uglify":"^1.2.0","ember-disable-prototype-extensions":"^1.1.2","ember-export-application-global":"^2.0.0","ember-load-initializers":"^1.0.0","ember-resolver":"^4.0.0","ember-source":"~2.14.1","loader.js":"^4.2.3"},"engines":{"node":"^4.5 || 6.* || >= 7.*"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"a289f59cb7ce70395d89bc7dd0515eb07edca044","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@1.1.0","_npmVersion":"6.5.0","_nodeVersion":"11.9.0","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"integrity":"sha512-llaJIAUjnQTZ7ydGRY4qcl6ZT9RkrvI9aSIEeBIjO/ekKaHsmUO55ti3V/QGFJOUJYd/cr5FRpRzNQW3hlPBvg==","shasum":"6aed64ee2c7e1c8f69bba73781e010e7033f0c49","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-1.1.0.tgz","fileCount":7,"unpackedSize":17592,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcbDlWCRA9TVsSAnZWagAAYBgP/0ZWYNBrGTQCYvmUJVY9\ntxMyuYgpSgOT9CrRolgpHhrfXZqEqmfG3xn+OE1bNPfMa4vEkE8LKPZC1Z7X\ni3Jsa8JMken8+zMcV+270RUb7ISJpuwY+9bHo81QxqRbYE3eOYYMcxVzNvtS\n+AM+QQVtv7rSeQlGHszGOK/qmVzOC4JrPEIZenSnNJ3JNLkmgnLmf4HLjWHP\nINNtQnpVih/gAhsEaiLGsRSF7iSmE47J7JWGF/G8rE0LANX5PLnHRkSKvZ+K\nlEmVNtx+Gw7gjaHqVO5eWWZUOkgJvSGhqRPDn3zzgM4Iz+cEa0Lgo1JmVSiO\n7KMXQ3dnAjU519DO4xtdaEELuDvkbhvOeRgX6FHQU6wQWXUUH4x5jJr2MOa6\ngOPjLKVAbwN4d0zZDWYOfAvGlO0yxGyAbm0ZpsaXXD6czlWLHYPqU4BGcl1b\nnYyooUGT8S++sTWYU97aA5iM3SeXy/bft8xPLeH2DvJlmyEmo78O6AeK3Trd\npVKjSv5b0NB1S+V+xCivjpbx7RY/f5aMfc6Auqpoy9jyNZxO8VGDZ8fsfgbL\nU++ZIcvCYrzE97BhaOWvo9AW/c+a+NsF7Jb8ZkQaEQ1zwPJ2k61DYqLejMzQ\ny1XU++r00EYcK4i38FRZ2mAu+abZlyYP9IWgVxO0Fci9CdSuz9XAlynwi1iQ\n4CTI\r\n=LTHn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDNa0ZVFkBEvGZS/0NIxSlYfHeONxNmS24HixZLvvMTtAIgO21wyBfvDeoKqJiY2ZwLDsfBy7Vu8aSii2U6hnpTDeU="}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_1.1.0_1550596437950_0.7763681778344445"},"_hasShrinkwrap":false},"1.1.1":{"name":"ember-cli-content-security-policy","version":"1.1.1","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"scripts":{"build":"ember build","start":"ember server","test":"ember try:each"},"dependencies":{"body-parser":"^1.17.0","chalk":"^2.0.0"},"devDependencies":{"broccoli-asset-rev":"^2.4.5","ember-ajax":"^3.0.0","ember-cli":"~2.14.2","ember-cli-babel":"^6.3.0","ember-cli-dependency-checker":"^1.3.0","ember-cli-eslint":"^3.0.0","ember-cli-htmlbars":"^2.0.1","ember-cli-htmlbars-inline-precompile":"^0.4.3","ember-cli-inject-live-reload":"^1.4.1","ember-cli-qunit":"^4.0.0","ember-cli-shims":"^1.1.0","ember-cli-sri":"^2.1.0","ember-cli-uglify":"^1.2.0","ember-disable-prototype-extensions":"^1.1.2","ember-export-application-global":"^2.0.0","ember-load-initializers":"^1.0.0","ember-resolver":"^4.0.0","ember-source":"~2.14.1","loader.js":"^4.2.3"},"engines":{"node":"^4.5 || 6.* || >= 7.*"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"gitHead":"4aabfa50496c720a76fa1e689ea43c04a40be875","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@1.1.1","_npmVersion":"6.5.0","_nodeVersion":"11.9.0","_npmUser":{"name":"rwjblue","email":"me@rwjblue.com"},"dist":{"integrity":"sha512-QgGAFt1nmsb0qF2YXI5iSM7jJVb09R2hrfX7uR+kkXMb5VyNQXdo2ZlX/DuIbePQVY4q9THpRh8Yf0UHJNbvDQ==","shasum":"7d91a695319d8f99c317f3a594fba77bbfedf6c7","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-1.1.1.tgz","fileCount":7,"unpackedSize":17553,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJcbcu7CRA9TVsSAnZWagAAJp0P/igrCe8rpDn7fK0i5n5+\nxF4hKlkUXRXZ/GujM8i58Caa5vWIR6TGn4bS8bLqvgZESgtUxsSYxsV6eApT\nRikYYViuNV1u3vqxN2q7VCOtl9+OxVCNiTxYzMxo8730r08afQ/0M/vDi+IT\nUYLtgzpLUqjKPDf2wk6dq3EXRqx1eXIBfd+bfdVh6zQgVuLO8QWwSTCjgqq3\nECssLxMtb664l959+0PJ1hbRJDaVsQxlgQtJexe/XmjKZ78TLWzCpp2embp9\nvayJP1ZzZMlKVjxU0dGfKY9CNf3ziJmVRrp6T2cdlSD8082hty0Sj1ih3WpC\nESOSMSvWNJjeMaAq6vu9rkJvwMUU/7vG9l6cI7gZswdcEAhrD6lZT+LuQP9m\nFGbI/EPpJvaoCE7OM+19NyJrH3t+70+M7Js4/dl7tp/QE0u3C19xaPJ/NWoi\n0mYI4Fj2v3bi7zpMQ8P4wqFO1V9foUEp9eRXYao8casqLEFT/zArfnkAiV0g\nL9RMCbrg6i9iBO10spJ7ar15KWrx4QYv2yLHyEd7rrc8Sam+cjurHErlfo74\n01Mxg+kHkSTWLkHfi6mFsl1Kb8DujSMOVPlIu+sfRcA3X4RRTo5IsKqJ5VE+\nLk1B7Jh3SSw4oJ6bfUrdDRAKa7Qel3BCtUvzgURrbRxWF7aRt4nDPI5Ho3S9\nRMwl\r\n=BcdQ\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD6sR9JBo6qT9BsS8xJ9JpjeoJHP5aUmLmhMLz8yGKOlQIgZRvFAbR+p9iXP4Sf6i54ZFlxu0Fn1Nrr8yzQh6IpBVk="}]},"maintainers":[{"name":"rwjblue","email":"robert.w.jackson@me.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_1.1.1_1550699450393_0.607650693861788"},"_hasShrinkwrap":false},"2.0.0-0":{"name":"ember-cli-content-security-policy","version":"2.0.0-0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint:hbs":"ember-template-lint .","lint:js":"eslint .","start":"ember serve","test":"ember test","test:all":"ember try:each","test:node":"for i in node-tests/*/*; do mocha $i; done"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.0.0","ember-cli-babel":"^7.17.2","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^1.3.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.0.3","broccoli-asset-rev":"^3.0.0","chai":"^4.2.0","denodeify":"^1.2.1","ember-cli":"~3.16.1","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-eslint":"^5.1.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^4.2.2","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-uglify":"^3.0.0","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.1","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^4.6.0","ember-resolver":"^7.0.0","ember-source":"~3.16.0","ember-source-channel-url":"^2.0.1","ember-try":"^1.4.0","eslint-plugin-ember":"^8.1.1","eslint-plugin-node":"^11.0.0","fs-extra":"^9.0.0","loader.js":"^4.7.0","mocha":"^7.0.0","qunit-dom":"^1.0.0","release-it":"^13.0.2","release-it-lerna-changelog":"^2.0.0","request":"^2.88.0"},"engines":{"node":"10.* || >= 12"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\nCompatibility\n------------------------------------------------------------------------------\n\n* Ember.js v2.18 or above\n* Ember CLI v3.4 or above\n* Node.js v10 or above\n\nInstallation\n------------------------------------------------------------------------------\n\n```bash\nember install ember-cli-content-security-policy\n```\n\nConfiguration\n------------------------------------------------------------------------------\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  'child-src' | 'connect-src' | 'default-src' | 'font-src' | 'frame-src' | 'image-src' | 'manifest-src' | 'media-src' | 'object-src' | 'prefetch-src' | 'script-src' | 'script-src-elem' | 'script-src-attr' | 'style-src' | 'style-src-elem' | 'style-src-attr' | 'worker-src' |\n  // Document Directives\n  'base-uri' | 'plugin-types' | 'sandbox' |\n  // Navigation Directives\n  'form-action' | 'form-ancestors' | 'navigate-to' |\n  // Reporting Directives\n  'report-uri' | 'report-uri' | 'report-to' |\n  // Directives Defined in Other Documents\n  'block-all-mixed-content' | 'upgrade-insecure-requests' | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string,\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean,\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true,\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: { [key: directiveName]: string[]; },\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean,\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nexport default function(environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src':  [\"'none'\"],\n      'script-src':   [\"'self'\"],\n      'font-src':     [\"'self'\"],\n      'connect-src':  [\"'self'\"],\n      'img-src':      [\"'self'\"],\n      'style-src':    [\"'self'\"],\n      'media-src':    [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n}\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src':  [\"'self'\", \"https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\"],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", \"http://fonts.gstatic.com\"],\n      // Allow data (xhr/websocket) from api.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", \"https://api.mixpanel.com\", \"https://custom-api.local\"],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", \"https://fonts.googleapis.com\"],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null\n    },\n    reportOnly: false\n  };\n};\n```\n\n\nFastBoot Integration\n------------------------------------------------------------------------------\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: [\"header\"],\n  };\n};\n```\n\n\nExternal Configuration\n------------------------------------------------------------------------------\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n\nDevelopment Support\n------------------------------------------------------------------------------\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n\nTest Support\n------------------------------------------------------------------------------\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n\nCompatibility with other addons\n------------------------------------------------------------------------------\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some very famous once.\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n\nDeprecations\n------------------------------------------------------------------------------\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"3ee936443fe0c77fefc39b02912869e54aa07260","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-0","_nodeVersion":"12.16.2","_npmVersion":"6.14.4","dist":{"integrity":"sha512-1XQJ3DNNVpH7bqtKeW+yNR2GpP5OVn0CUNhehYgR8COlJ3K+v8HijpCTldR0JKH1ha0gm3dLf/ewE9kvzPWa4w==","shasum":"7534b345a9d6b16ffc5d5106d53fbbe78a030005","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-0.tgz","fileCount":13,"unpackedSize":44634,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJelC/TCRA9TVsSAnZWagAAeykQAJz7f83sdOCVUcmglKgy\ndQntZo7uuEIPLdV2e0iIKHsO2ugeP8VPdTEpQsksid/l/7M+NimsT4u7Fgre\nx0MwJPTlOMCJIOqWkXa8S7B6kyKWgGaI+OHwDHnR8GBcI5SGHDdohtQ57lBN\nTBC0Kmuhau4+goHfDDhAI+CLUUlotvRL++oPrL/9sS+tbCWp2vBaeAOfXd8N\nOfcWwxAjG3QvGn8dUlTK4W5l3h6341fnrvJwr2FCrpoUpgMesgDJK3P7O2f5\ngXvcnjSKJTVS77tGSRm2V/cFNkvbyasRnRuacE604A7ArhI6+NfVDOahD+Ui\nM72JaVgaDlsInmsSIqZoDtiGiQJAjrvLD5CtWrImu1gurdY2cnII6rH94fpV\nIbU3HBETqYoZ2xc9N1fwbTCF5p0v63F2IdMyl5QS2Wp9bZ98s6FXS8SSWcua\n1D5lMUFPtaLL7OjssLfP258H8eWXO3qc/4FaoSs+UA+9j7aZ+fnSfHx9Pnk5\npoKyltuxUFAXdlUa8U1hJHd3CsKnpxq4+H4o41VRhWgmgRksbI6BNznUDYym\nv8Jz5OKfXO4MbV7b3DVeYKMg9/3Gmz2+5fJJ6vB1RYdp/WU/2OIFMy2CcWF6\n9jbe/kdtwS1UCuKFDB2pZcSus4xaIYkX4CS2Lt8IK4lbS9W1qxORez0TPKID\noSib\r\n=rHhn\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA/U9mB1huuvcYr/gdiqr6dodMGReV0YzqXGRwQ1xBj1AiAy52PjltGfSF/qsHFWN9V958BJvK0r5EbNm/VBLAmQAA=="}]},"maintainers":[{"email":"npm@jhanschke.de","name":"jelhan"},{"email":"me@rwjblue.com","name":"rwjblue"}],"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-0_1586769874624_0.9287333592984581"},"_hasShrinkwrap":false},"2.0.0-1":{"name":"ember-cli-content-security-policy","version":"2.0.0-1","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint:hbs":"ember-template-lint .","lint:js":"eslint .","start":"ember serve","test":"ember test","test:all":"ember try:each","test:node":"for i in node-tests/*/*; do mocha $i; done"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.0.0","ember-cli-babel":"^7.17.2","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^1.3.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.0.3","broccoli-asset-rev":"^3.0.0","chai":"^4.2.0","denodeify":"^1.2.1","ember-cli":"~3.16.1","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-eslint":"^5.1.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^4.2.2","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-uglify":"^3.0.0","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.1","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^4.6.0","ember-resolver":"^7.0.0","ember-source":"~3.16.0","ember-source-channel-url":"^2.0.1","ember-try":"^1.4.0","eslint-plugin-ember":"^8.1.1","eslint-plugin-node":"^11.0.0","fs-extra":"^9.0.0","loader.js":"^4.7.0","mocha":"^7.0.0","qunit-dom":"^1.0.0","release-it":"^13.0.2","release-it-lerna-changelog":"^2.0.0","request":"^2.88.0"},"engines":{"node":"10.* || >= 12"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\nCompatibility\n------------------------------------------------------------------------------\n\n* Ember.js v2.18 or above\n* Ember CLI v3.4 or above\n* Node.js v10 or above\n\nInstallation\n------------------------------------------------------------------------------\n\n```bash\nember install ember-cli-content-security-policy\n```\n\nConfiguration\n------------------------------------------------------------------------------\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  'child-src' | 'connect-src' | 'default-src' | 'font-src' | 'frame-src' | 'image-src' | 'manifest-src' | 'media-src' | 'object-src' | 'prefetch-src' | 'script-src' | 'script-src-elem' | 'script-src-attr' | 'style-src' | 'style-src-elem' | 'style-src-attr' | 'worker-src' |\n  // Document Directives\n  'base-uri' | 'plugin-types' | 'sandbox' |\n  // Navigation Directives\n  'form-action' | 'form-ancestors' | 'navigate-to' |\n  // Reporting Directives\n  'report-uri' | 'report-uri' | 'report-to' |\n  // Directives Defined in Other Documents\n  'block-all-mixed-content' | 'upgrade-insecure-requests' | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string,\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean,\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true,\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: { [key: directiveName]: string[]; },\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean,\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src':  [\"'none'\"],\n      'script-src':   [\"'self'\"],\n      'font-src':     [\"'self'\"],\n      'connect-src':  [\"'self'\"],\n      'img-src':      [\"'self'\"],\n      'style-src':    [\"'self'\"],\n      'media-src':    [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n}\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src':  [\"'self'\", \"https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\"],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", \"http://fonts.gstatic.com\"],\n      // Allow data (xhr/websocket) from api.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", \"https://api.mixpanel.com\", \"https://custom-api.local\"],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", \"https://fonts.googleapis.com\"],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null\n    },\n    reportOnly: false\n  };\n};\n```\n\n\nFastBoot Integration\n------------------------------------------------------------------------------\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: [\"header\"],\n  };\n};\n```\n\n\nExternal Configuration\n------------------------------------------------------------------------------\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n\nDevelopment Support\n------------------------------------------------------------------------------\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n\nTest Support\n------------------------------------------------------------------------------\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function(environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n\nCompatibility with other addons\n------------------------------------------------------------------------------\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some very famous once.\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n\nDeprecations\n------------------------------------------------------------------------------\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"58c038259e48be540e7cd29be882fee386cb32d1","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-1","_nodeVersion":"12.16.2","_npmVersion":"6.14.4","dist":{"integrity":"sha512-Iz2qFGZdNYQony/v1rp19ohAHE/JNoz4+MsK2E0XDLRTuFVeIOvpCLp+7On0915taQi+RkG8GyC46XM1IagMsQ==","shasum":"ed54e506cd51e9566b05ea1f5d3e886f47fd18ed","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-1.tgz","fileCount":13,"unpackedSize":45038,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJelrPOCRA9TVsSAnZWagAAEEEP/RP4SUvwM/QF2+JcGUjV\nqvxyt+8h1Sbmqrd/hVVWDyakOY5ahPwe1YYLdp/UQpk4tabC3FvdtPbMxyxP\nl5+81cmA/BZq30WjfW5DtbYqwMS1etcBh+ykeyMIrqO0kIqQ/NcbIWp9mmkd\nfvAmqvh5CI+5MxKl/O8cw8vnbW0UdrItRJjrLX/gcBft8/hwVf2x52nWtepC\nCP+3KDJNE0N4DvSr1rrH+vwpMuJ6jrG/YsgUVx0vRUe+Bt07B7T+Q3LlHwAV\nZ2yZIyBsSu7pisuWfTmPRZSPl1q13PwrB7FLZzyEydAZBUi0rlOlognOCbLX\n969/h40XZzXumnc6k7PvrseKngrtwQXQqivHthYRjXULf7MRHrJ1BMdXGa5k\nTH3Ehkzv3CnQBwkQEsgvWkjp8Mwz0hSMF0JOvYmy7Yr5ll1C+aKhslEUJh9l\nypbLvFnMX5nmGU1iKMfEh/sKPM8hgT23UVPWyPfQQN7Rhe9gl08BVcXP5qBa\n1OVTjAaHgeILEBtYu9mosuNNSP0JKDg7XUL21gzMZb88brBHOI62/hGCvo41\nQME90YdrSTCZIs71kVQn+N5BYIf0BgOHyEmeZsP4MTPSKHFLGAJFuA6mAa6P\nDWfARaC2BPwSy1xGtiWzRB+XAouc0bIHfeMmHt8CIpgzZEesuUXYLic0+8ri\nLQJv\r\n=PZQ6\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGO32OsbKMV1lru6XvznyX216MFKwPxu69x/9NgUD1FDAiAA5sXcgr2ZXSyKZAFTd3hK5xgTmwBjG8UXQtjW2uvjAQ=="}]},"maintainers":[{"email":"npm@jhanschke.de","name":"jelhan"},{"email":"me@rwjblue.com","name":"rwjblue"}],"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-1_1586934733853_0.7484771455783672"},"_hasShrinkwrap":false},"2.0.0-2":{"name":"ember-cli-content-security-policy","version":"2.0.0-2","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.0.0","debug":"^4.3.1","ember-cli-babel":"^7.17.2","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^1.3.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.0.3","broccoli-asset-rev":"^3.0.0","chai":"^4.2.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.16.1","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-eslint":"^5.1.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^4.2.2","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-uglify":"^3.0.0","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.1","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^4.6.0","ember-resolver":"^7.0.0","ember-source":"~3.16.0","ember-source-channel-url":"^2.0.1","ember-try":"^1.4.0","eslint-config-prettier":"^6.15.0","eslint-plugin-ember":"^8.1.1","eslint-plugin-node":"^11.0.0","eslint-plugin-prettier":"^3.1.4","execa":"^4.1.0","fs-extra":"^9.0.0","loader.js":"^4.7.0","mocha":"^7.0.0","npm-run-all":"^4.1.5","prettier":"2.1.2","qunit-dom":"^1.0.0","release-it":"^14.2.2","release-it-lerna-changelog":"^3.1.0","request":"^2.88.0","semver":"^7.3.2"},"engines":{"node":"10.* || >= 12"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\n## Compatibility\n\n- Ember.js v2.18 or above\n- Ember CLI v3.4 or above\n- Node.js v10 or above\n\n## Installation\n\n```bash\nember install ember-cli-content-security-policy\n```\n\n## Configuration\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  | 'child-src'\n  | 'connect-src'\n  | 'default-src'\n  | 'font-src'\n  | 'frame-src'\n  | 'image-src'\n  | 'manifest-src'\n  | 'media-src'\n  | 'object-src'\n  | 'prefetch-src'\n  | 'script-src'\n  | 'script-src-elem'\n  | 'script-src-attr'\n  | 'style-src'\n  | 'style-src-elem'\n  | 'style-src-attr'\n  | 'worker-src'\n  // Document Directives\n  | 'base-uri'\n  | 'plugin-types'\n  | 'sandbox'\n  // Navigation Directives\n  | 'form-action'\n  | 'form-ancestors'\n  | 'navigate-to'\n  // Reporting Directives\n  | 'report-uri'\n  | 'report-uri'\n  | 'report-to'\n  // Directives Defined in Other Documents\n  | 'block-all-mixed-content'\n  | 'upgrade-insecure-requests'\n  | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string;\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean;\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true;\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: {[key: directiveName]: string[]};\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean;\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src': [\"'none'\"],\n      'script-src': [\"'self'\"],\n      'font-src': [\"'self'\"],\n      'connect-src': [\"'self'\"],\n      'img-src': [\"'self'\"],\n      'style-src': [\"'self'\"],\n      'media-src': [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n};\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\nChanges to the configuration require a restart of a running Ember development server instance.\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src': [\"'self'\", 'https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js'],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", 'http://fonts.gstatic.com'],\n      // Allow data (xhr/websocket) from api-js.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", 'https://api-js.mixpanel.com', 'https://custom-api.local'],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", 'https://fonts.googleapis.com'],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null,\n    },\n    reportOnly: false,\n  };\n};\n```\n\n## FastBoot Integration\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: ['header'],\n  };\n};\n```\n\n## External Configuration\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n## Development Support\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n## Test Support\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n## Compatibility with other addons\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some famous once. <!-- This docs should only include addons that are in Top 100 list provided by Ember Observer. -->\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n### ember-cli-code-coverage\n\nEmber-cli-code-coverage uses Istanbul, which injects `new Function('return this')` by default into the app. This requires `'unsafe-eval'` to be allowed by the script directive. Currently there isn't any other option than either adding `'unsafe-eval'` to script directive if code coverage is enabled or disable CSP at all. Details could be found in [this issue](https://github.com/kategengler/ember-cli-code-coverage/issues/214).\n\n## Deprecations\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"a786de7d9bdcd6d549a920ab9ab2a1b5d02a1aae","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-2","_nodeVersion":"14.15.4","_npmVersion":"6.14.10","dist":{"integrity":"sha512-R3luNiZaIcrmxBH7NLTiyRc56s7r9arrF+M8BzonVHvILoOFSRAPaJrC4b7P9CNpq3zvdrE7AiMKHpCeK13T5g==","shasum":"92a1fbb59a61cc48d244d56eea80468887e1159a","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-2.tgz","fileCount":19,"unpackedSize":585477,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJf+esoCRA9TVsSAnZWagAAkGoQAJ3SKX03TUgVnrLzL+HL\nJtVbg/Ae5ACGh8xqJhNob97KybC3RYFSMj7FboplAIXDlH0bVSAe7JBt9jra\nUV/4mYaf0ZiHHifL8gApyN+tP/B9UbOZsBWw6NHaP5dZam3XFQP8y2WuwLgO\nI9OAvRgN16BsdiuPJu7TgSQsk1GdJc7oyfIOAV+yM5ibfR3Qz3KJUFLtFjcT\n/n5bX+06yYrbQrn8ACRtcGpfvO1MWeHhE44Kfm5gHTwNLdNzyL7MdSOcz1ED\n1BrH9tpTT0TEol7Fg1kUy36c21KjjLUBIn7pwVkADI2R7btdulI17MCg+0M+\nHwrO3Ar1VPXQEmak0rCavZE1qFwAB8H6lXHmd/u2Af5oywSzmrF520c6enOX\nuQfmwzaEiDq8OkBHss8ZcgclkjrmV0kty/NHNGD6WFlLzKMPuUhK63zd4y+c\n35C7BXSnOgUcaMJqK/q6NJYcTtFR8x6DIp1ZQxzJwyDSQiR6NP4eDzDfbtjk\nkQ9TbKwbOhTYILPFvNrrKdROVEuwAOZVQV/vfsZTIp6Pw+HmXaE0EfoCkPFO\ni68YlUupOTgb5MBpr6cWONcmZkJJfMq05JMrr/ImpSF7soDMn3UrZtMKmXnc\nwWMSHHKhHA2QP2np9QjKp/6FfBtqyXq5o5TNAZ0L8Oxn6vcTGQL/vIjftQNi\nnwE1\r\n=EP3j\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC6beJkosl3QWNEpRYQ7c0+bhyawKms/Wa7qP3TMc8/0QIhAMNv2ygl01e0a+UMEXOQbamABpb2GWIK18uc1PhZl6MX"}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-2_1610214184127_0.40280359128461174"},"_hasShrinkwrap":false},"2.0.0-3":{"name":"ember-cli-content-security-policy","version":"2.0.0-3","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.0.0","debug":"^4.3.1","ember-cli-babel":"^7.17.2","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.0.3","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.16.1","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-eslint":"^5.1.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^5.3.1","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-uglify":"^3.0.0","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^4.6.0","ember-resolver":"^8.0.2","ember-source":"~3.25.1","ember-source-channel-url":"^3.0.0","ember-try":"^1.4.0","eslint-config-prettier":"^7.2.0","eslint-plugin-ember":"^8.14.0","eslint-plugin-node":"^11.0.0","eslint-plugin-prettier":"^3.1.4","execa":"^4.1.0","fs-extra":"^9.1.0","loader.js":"^4.7.0","mocha":"^7.0.0","npm-run-all":"^4.1.5","prettier":"2.2.1","qunit-dom":"^1.0.0","release-it":"^14.4.1","release-it-lerna-changelog":"^3.1.0","request":"^2.88.0","semver":"^7.3.2"},"engines":{"node":"10.* || >= 12"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\n## Compatibility\n\n- Ember.js v2.18 or above\n- Ember CLI v3.4 or above\n- Node.js v10 or above\n\n## Installation\n\n```bash\nember install ember-cli-content-security-policy\n```\n\n## Configuration\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  | 'child-src'\n  | 'connect-src'\n  | 'default-src'\n  | 'font-src'\n  | 'frame-src'\n  | 'image-src'\n  | 'manifest-src'\n  | 'media-src'\n  | 'object-src'\n  | 'prefetch-src'\n  | 'script-src'\n  | 'script-src-elem'\n  | 'script-src-attr'\n  | 'style-src'\n  | 'style-src-elem'\n  | 'style-src-attr'\n  | 'worker-src'\n  // Document Directives\n  | 'base-uri'\n  | 'plugin-types'\n  | 'sandbox'\n  // Navigation Directives\n  | 'form-action'\n  | 'frame-ancestors'\n  | 'navigate-to'\n  // Reporting Directives\n  | 'report-uri'\n  | 'report-to'\n  // Directives Defined in Other Documents\n  | 'block-all-mixed-content'\n  | 'upgrade-insecure-requests'\n  | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string;\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean;\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true;\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: {[key: directiveName]: string[]};\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean;\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src': [\"'none'\"],\n      'script-src': [\"'self'\"],\n      'font-src': [\"'self'\"],\n      'connect-src': [\"'self'\"],\n      'img-src': [\"'self'\"],\n      'style-src': [\"'self'\"],\n      'media-src': [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n};\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\nChanges to the configuration require a restart of a running Ember development server instance.\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src': [\"'self'\", 'https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js'],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", 'http://fonts.gstatic.com'],\n      // Allow data (xhr/websocket) from api-js.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", 'https://api-js.mixpanel.com', 'https://custom-api.local'],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", 'https://fonts.googleapis.com'],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null,\n    },\n    reportOnly: false,\n  };\n};\n```\n\n## FastBoot Integration\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: ['header'],\n  };\n};\n```\n\n## External Configuration\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n## Development Support\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n## Test Support\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n## Compatibility with other addons\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some famous once. <!-- This docs should only include addons that are in Top 100 list provided by Ember Observer. -->\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n### ember-cli-code-coverage\n\nEmber-cli-code-coverage uses Istanbul, which injects `new Function('return this')` by default into the app. This requires `'unsafe-eval'` to be allowed by the script directive. Currently there isn't any other option than either adding `'unsafe-eval'` to script directive if code coverage is enabled or disable CSP at all. Details could be found in [this issue](https://github.com/kategengler/ember-cli-code-coverage/issues/214).\n\n## Deprecations\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"a744b2e19c2fd5f237fb63eff16a0030e3a56a10","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-3","_nodeVersion":"14.16.1","_npmVersion":"6.14.12","dist":{"integrity":"sha512-Vf1q0gcWKwzxsPsaaA9ZE4csI4x3Cp9L1DQiJIN8V1KEXlrKMYe575SxDJHH54tgyNor3/0+7dRtKG5zIUdA3Q==","shasum":"45e28d623688bf4ed773db6e6f4953229b83a7d1","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-3.tgz","fileCount":19,"unpackedSize":586518,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJged2TCRA9TVsSAnZWagAA9PsQAJoXKcgfK1Xlduzty+iB\nNBwNdkIyCybXGDp6c00g/+UMS4legQEXugQ7hdG4Z+DaaW/r67bvIeFMrpmq\nSiHLrIqyEazXT1Tj7e0jnMmAXcg9k9NhQS00LBpel3AhcoMDp+mibsgJnnv6\nqHsDpzUbzTVtZh6PbVoDbgbqC8FL/NLPm17F2fo0owjgsQpR08IgsGlfGj1w\nK+Ld4deQJcLyTX0anya1lmQ1H7n8vxCpBql6lvDNNkFy/ErGP1BhI0kQet0k\nUJXt6vVwFrlPRn6hdsEPqacCm7BhUORzROnIpA7dj9K2tk4pw8QUhAxDtY6Z\nZj7lPSFNTCJD20Wwwmg3e8HF1VPFVz/cEyUSncG08KBvt/5lnksxzCrbIXA1\nt0BfhgzbjIxjYvUjrIp9l8yDjLNGikqZI+HK7qywiZnq6Kh43yhY1rpxy+av\nNJgAkSM1VKlCJO3r3cE5orAZRvuf+qQaGYqSCNjNTDRyoo12zcK2mVwWtKG1\n7fGAwyftCTE8FwDNyyayTh65Kn3C8Z2kVQSnRWCLtfdiF6Av4uF23Eop+ynl\npAVlll/OZ1hn3EapiQErYBEqxjL+PJITLvsbiCzdxMzAxXx6X7StvbcRy6LT\n9gE+LvJmyBoRACxtpxvD6oy7o7Th9leEVHucnxAYm2ZINvhvOgliHbQuHKNL\n2rLI\r\n=0Jea\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAF9nBFq/qPTdnjLvv6U9UHwuNzXPCMi8ZEpdIKXpL7tAiEA9uSa0JCS9ULGVTpUwjnQtCJkt8jj9tyaEFDqeo6Kn5g="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-3_1618599314332_0.8431717333269717"},"_hasShrinkwrap":false},"2.0.0-4":{"name":"ember-cli-content-security-policy","version":"2.0.0-4","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.17.2","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.0.3","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.16.1","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-eslint":"^5.1.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^5.7.1","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-uglify":"^3.0.0","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^4.6.0","ember-resolver":"^8.0.2","ember-source":"~3.25.1","ember-source-channel-url":"^3.0.0","ember-try":"^1.4.0","eslint-config-prettier":"^7.2.0","eslint-plugin-ember":"^8.14.0","eslint-plugin-node":"^11.0.0","eslint-plugin-prettier":"^3.1.4","execa":"^4.1.0","fs-extra":"^9.1.0","loader.js":"^4.7.0","mocha":"^7.0.0","npm-run-all":"^4.1.5","prettier":"2.2.1","qunit-dom":"^1.0.0","release-it":"^14.4.1","release-it-lerna-changelog":"^3.1.0","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"10.* || >= 12"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\n## Compatibility\n\n- Ember.js v2.18 or above\n- Ember CLI v3.4 or above\n- Node.js v10 or above\n\n## Installation\n\n```bash\nember install ember-cli-content-security-policy\n```\n\n## Configuration\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  | 'child-src'\n  | 'connect-src'\n  | 'default-src'\n  | 'font-src'\n  | 'frame-src'\n  | 'image-src'\n  | 'manifest-src'\n  | 'media-src'\n  | 'object-src'\n  | 'prefetch-src'\n  | 'script-src'\n  | 'script-src-elem'\n  | 'script-src-attr'\n  | 'style-src'\n  | 'style-src-elem'\n  | 'style-src-attr'\n  | 'worker-src'\n  // Document Directives\n  | 'base-uri'\n  | 'plugin-types'\n  | 'sandbox'\n  // Navigation Directives\n  | 'form-action'\n  | 'frame-ancestors'\n  | 'navigate-to'\n  // Reporting Directives\n  | 'report-uri'\n  | 'report-to'\n  // Directives Defined in Other Documents\n  | 'block-all-mixed-content'\n  | 'upgrade-insecure-requests'\n  | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string;\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean;\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true;\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: {[key: directiveName]: string[]};\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean;\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src': [\"'none'\"],\n      'script-src': [\"'self'\"],\n      'font-src': [\"'self'\"],\n      'connect-src': [\"'self'\"],\n      'img-src': [\"'self'\"],\n      'style-src': [\"'self'\"],\n      'media-src': [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n};\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\nChanges to the configuration require a restart of a running Ember development server instance.\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src': [\"'self'\", 'https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js'],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", 'http://fonts.gstatic.com'],\n      // Allow data (xhr/websocket) from api-js.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", 'https://api-js.mixpanel.com', 'https://custom-api.local'],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", 'https://fonts.googleapis.com'],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null,\n    },\n    reportOnly: false,\n  };\n};\n```\n\n## FastBoot Integration\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: ['header'],\n  };\n};\n```\n\n## External Configuration\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n## Development Support\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n## Test Support\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n## Compatibility with other addons\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some famous once. <!-- This docs should only include addons that are in Top 100 list provided by Ember Observer. -->\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n### ember-cli-code-coverage\n\nEmber-cli-code-coverage uses Istanbul, which injects `new Function('return this')` by default into the app. This requires `'unsafe-eval'` to be allowed by the script directive. Currently there isn't any other option than either adding `'unsafe-eval'` to script directive if code coverage is enabled or disable CSP at all. Details could be found in [this issue](https://github.com/kategengler/ember-cli-code-coverage/issues/214).\n\n## Deprecations\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"759e42512219dd3b8721cd90d68ed405db450588","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-4","_nodeVersion":"14.16.1","_npmVersion":"6.14.12","dist":{"integrity":"sha512-pmJcR4ABodKQDNYgpWVHqbFsm6/wLJrfPvwVcUY5CFQGbZaKNmkzuTqkntUdnQZQ2+WSNcwDVRtJLpyBsTw75A==","shasum":"4552187dcfc8f0ed4979e9a33146e321bc4f5c1d","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-4.tgz","fileCount":19,"unpackedSize":586589,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJgk/wXCRA9TVsSAnZWagAA4ykP/2dBFQ2sXsWAPHWSs1bu\nXu8/ED/6jsLudwzw3z0G3U+GGqQPoSix1NOGQd6AVVNeVcFKYeIFGP/8uKDy\nHJniAriuKgD8bfWi0tf3vz8EGYl/RxbwfJMZnDTsBuHr50BR7Fk8P6I3YAUh\nI9HrZhCQT0ZLZKL5PitA6ggTsM0SFDJUSJIWA0rgn7cVlPZ+YJoHcIRBa218\nOTlXq7hBfWuaQjAemjbowslKswh8zAH8slqGKKPLYkXUfJgU2Se35SGahaeC\nwuLMjXuBMgLAL96jGgDV9IB3NfAOI6APUdD61oW9pcYceKTglrWodrKIIVyR\nE69k+N+fPxieciG08xxtoZnvFxbEad1qJ0Y2xH4Zrnlr2JdoVYsNSPPkiQxo\nY0FD65U7ckji95QuxxJAaQeUjfEmsCkrZfWZFaQuauwzBAnqlFOLXi/41KeY\nn3/8q5dlAAhHmINUPnwAmgt6dUJh1VYuhL1DcrceBGWCSy+71ZwmP+9/vSRu\nfV5GCMNYKPPYafKT0UzAvd/k0qKCqKSUCaSBPIpnz7YKsQpyWGhhyI0Syj1r\nYVnpCSI5klQfMBWty5aCZMD/5sPC2R2SCoWzz9aTF3p46YEism45sAXfXy9k\njhdwK2QiE83MoAqp6P2uiLtrna9s5F3Ve4FBwEozNtZlYpaOOOY3HHPLz+0H\n8cnB\r\n=8GYV\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDJNrpABTeKy+uyvfB8mGp7JYLWg2PM/Ccq7sB2k77iUwIgF8VPYX6xPaFBm8Zw3/RFuewbehHdhZ1uXYb0KSWBE+g="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-4_1620311062613_0.1271158541647519"},"_hasShrinkwrap":false},"2.0.0-5":{"name":"ember-cli-content-security-policy","version":"2.0.0-5","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.26.3","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@ember/test-helpers":"^2.2.5","@embroider/test-setup":"^0.37.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.1.0","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.26.0","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^5.7.1","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-terser":"^4.0.1","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^5.1.4","ember-resolver":"^8.0.2","ember-source":"~3.26.1","ember-source-channel-url":"^3.0.0","ember-try":"^1.4.0","eslint":"^7.23.0","eslint-config-prettier":"^8.1.0","eslint-plugin-ember":"^10.3.0","eslint-plugin-node":"^11.1.0","eslint-plugin-prettier":"^3.3.1","execa":"^4.1.0","fs-extra":"^9.1.0","loader.js":"^4.7.0","mocha":"^7.0.0","npm-run-all":"^4.1.5","prettier":"~2.2.1","qunit":"^2.14.1","qunit-dom":"^1.6.0","release-it":"^14.4.1","release-it-lerna-changelog":"^3.1.0","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"12.* || 14.* || >= 16"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\n## Compatibility\n\n- Ember.js v2.18 or above\n- Ember CLI v3.4 or above\n- Node.js v12 or above\n\n## Installation\n\n```bash\nember install ember-cli-content-security-policy\n```\n\n## Configuration\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  | 'child-src'\n  | 'connect-src'\n  | 'default-src'\n  | 'font-src'\n  | 'frame-src'\n  | 'image-src'\n  | 'manifest-src'\n  | 'media-src'\n  | 'object-src'\n  | 'prefetch-src'\n  | 'script-src'\n  | 'script-src-elem'\n  | 'script-src-attr'\n  | 'style-src'\n  | 'style-src-elem'\n  | 'style-src-attr'\n  | 'worker-src'\n  // Document Directives\n  | 'base-uri'\n  | 'plugin-types'\n  | 'sandbox'\n  // Navigation Directives\n  | 'form-action'\n  | 'frame-ancestors'\n  | 'navigate-to'\n  // Reporting Directives\n  | 'report-uri'\n  | 'report-to'\n  // Directives Defined in Other Documents\n  | 'block-all-mixed-content'\n  | 'upgrade-insecure-requests'\n  | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string;\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean;\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true;\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: {[key: directiveName]: string[]};\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean;\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src': [\"'none'\"],\n      'script-src': [\"'self'\"],\n      'font-src': [\"'self'\"],\n      'connect-src': [\"'self'\"],\n      'img-src': [\"'self'\"],\n      'style-src': [\"'self'\"],\n      'media-src': [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n};\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\nChanges to the configuration require a restart of a running Ember development server instance.\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src': [\"'self'\", 'https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js'],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", 'http://fonts.gstatic.com'],\n      // Allow data (xhr/websocket) from api-js.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", 'https://api-js.mixpanel.com', 'https://custom-api.local'],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", 'https://fonts.googleapis.com'],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null,\n    },\n    reportOnly: false,\n  };\n};\n```\n\n## FastBoot Integration\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: ['header'],\n  };\n};\n```\n\n## External Configuration\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n## Development Support\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n## Test Support\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n## Compatibility with other addons\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some famous once. <!-- This docs should only include addons that are in Top 100 list provided by Ember Observer. -->\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n### Embroider\n\n[Webpack](https://webpack.js.org/), which is used by [Embroider](https://github.com/embroider-build/embroider), uses the `eval` function by default in development builds to generate a source map. This violates the default CSP policy. It's recommended to configure Webpack to use [`'source-map'` strategy to generate source maps](https://webpack.js.org/configuration/devtool/). To do so, add the following Embroider configuration:\n\n```js\nreturn require('@embroider/compat').compatBuild(app, Webpack, {\n  packagerOptions: {\n    // other configuration\n    webpackConfig: {\n      devtool: 'source-map',\n    },\n  },\n});\n```\n\nFor addons using `maybeEmbroider` utility provided by `@embroider/test-setup` the configuration looks like this:\n\n```js\nconst { maybeEmbroider } = require('@embroider/test-setup');\nreturn maybeEmbroider(app, {\n  // other configuration\n  packagerOptions: {\n    webpackConfig: {\n      devtool: 'source-map',\n    },\n  },\n});\n```\n\n### ember-cli-code-coverage\n\nEmber-cli-code-coverage uses Istanbul, which injects `new Function('return this')` by default into the app. This requires `'unsafe-eval'` to be allowed by the script directive. Currently there isn't any other option than either adding `'unsafe-eval'` to script directive if code coverage is enabled or disable CSP at all. Details could be found in [this issue](https://github.com/kategengler/ember-cli-code-coverage/issues/214).\n\n## Deprecations\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","readmeFilename":"README.md","gitHead":"a53418f27a0d182e7010b79839e42904c9708521","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0-5","_nodeVersion":"16.13.0","_npmVersion":"8.1.0","dist":{"integrity":"sha512-QjdJpDQTTF1gAxDjTO4WqeNPRJwZHt+M7YfFRz9flK/uy8b2iixvg4GqgnvYhXyiZ+TzEb9arNZQ4OmtO5y8yw==","shasum":"ebbd4979025720b3a860ae8dec9324379e875ab3","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0-5.tgz","fileCount":18,"unpackedSize":541423,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHkwf6gkiO4MXyosYntVLGP3FpV06MCNsPNxTGHDWigtAiBPSXRbVZEXQ0hNvZ+ibUTE5IDsCFOAXIn9oKX+8r/GgQ=="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0-5_1635462640099_0.8443295903872021"},"_hasShrinkwrap":false},"2.0.0":{"name":"ember-cli-content-security-policy","version":"2.0.0","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.26.3","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@ember/test-helpers":"^2.2.5","@embroider/test-setup":"^0.37.0","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.1.0","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.26.0","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-fastboot":"^2.2.1","ember-cli-htmlbars":"^5.7.1","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-terser":"^4.0.1","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^0.1.6","ember-qunit":"^5.1.4","ember-resolver":"^8.0.2","ember-source":"~3.28.4","ember-source-channel-url":"^3.0.0","ember-try":"^1.4.0","eslint":"^7.23.0","eslint-config-prettier":"^8.1.0","eslint-plugin-ember":"^10.3.0","eslint-plugin-node":"^11.1.0","eslint-plugin-prettier":"^4.0.0","execa":"^5.1.1","fs-extra":"^9.1.0","loader.js":"^4.7.0","mocha":"^7.0.0","npm-run-all":"^4.1.5","prettier":"~2.2.1","qunit":"^2.14.1","qunit-dom":"^2.0.0","release-it":"^14.4.1","release-it-lerna-changelog":"^3.1.0","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"12.* || 14.* || >= 16"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"gitHead":"d026ee690ab5cdad6d00df61d009c093a759e672","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.0","_nodeVersion":"16.13.0","_npmVersion":"8.1.0","dist":{"integrity":"sha512-LjV8AEvhyPzq07Pkh1DN03GMRp1IupMhPWYiOryaz8HVnAubmBprHlbBbJTSEdRxHB48Dw1Ud8jZAPiUN+4Bbg==","shasum":"1dc0d743799e237ba84d58d5cfa227d70492be8b","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.0.tgz","fileCount":18,"unpackedSize":541542,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDcs2zZ/ScT8PclBNCGbreuswGms4Hq0nvOVxtw7of65wIgDipaSX4h2sEndqLEkwUdDv7z2LF6tJniTBx/fhfHvjc="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.0_1636730819736_0.8013497341398181"},"_hasShrinkwrap":false},"2.0.1":{"name":"ember-cli-content-security-policy","version":"2.0.1","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.26.3","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@ember/test-helpers":"^2.6.0","@embroider/test-setup":"^0.47.1","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.1.0","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.26.0","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-fastboot":"^3.2.0-beta.4","ember-cli-htmlbars":"^6.0.0","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-terser":"^4.0.1","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^1.0.0","ember-qunit":"^5.1.4","ember-resolver":"^8.0.2","ember-source":"~3.28.4","ember-source-channel-url":"^3.0.0","ember-try":"^2.0.0","eslint":"^7.23.0","eslint-config-prettier":"^8.1.0","eslint-plugin-ember":"^10.5.8","eslint-plugin-node":"^11.1.0","eslint-plugin-prettier":"^4.0.0","execa":"^5.1.1","fs-extra":"^10.0.0","loader.js":"^4.7.0","mocha":"^9.1.3","npm-run-all":"^4.1.5","prettier":"~2.5.0","qunit":"^2.14.1","qunit-dom":"^2.0.0","release-it":"^14.11.8","release-it-lerna-changelog":"^4.0.1","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"12.* || 14.* || >= 16"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"gitHead":"e544cfec9881234b74b7df8e38f9ebdc9f7fb459","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.1","_nodeVersion":"16.13.1","_npmVersion":"8.1.2","dist":{"integrity":"sha512-jhwH9Jse180PQeqMRtvJuMqlWuB5QqpPTaKKcsH3RhwMo/rkCZI5SXyvVS9o9jnMFk0VJJvri97YyNj8OG/Udg==","shasum":"106a94ca8337b3f5552880a44016d5674a3681ea","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.1.tgz","fileCount":18,"unpackedSize":542129,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhtv3SCRA9TVsSAnZWagAAOIoP/i3fsy0GN+XWCIqZGC0q\nzjqs/n8je+F5f2Cvjdl2OLS02Gd4s0rV9pmHgbuOhuZincyqx6on18q2HS7E\n4Z3XQNHM2Scon98fu5DdZRdBVHHn5odRE8+WO+q2TMRmhGvVgkvO3swfoDU/\nfqhlB9EM69sFTZtZC4TSChwXyD0n/nGqu0/elGcP+9Hsd+QqylNhHU8qDrKI\nLsB7+SLLWFQUUnsNXeTlXIFfCfv79JHHwdL2oq9g94qqDMTo9o8gn0eAv679\nki7w1piteN+N5ABoAbEAtsdhQsZxNBoW88giQsCKM7VmjOJjgsIXAzb1NGj8\nXQ1JyrK7hqiux9XlYW5acY0WO10YJnABzFaOlfCtHzcSQzv5b1gHJjjJB8dR\nG/DgaXxh/IpV4Niw3DtDHq2rvz7dAYsQvME2dW1rMRJNvtNwaYzPlABmE8Xq\nvcK9H/km21PaoUlmblbyZxN9+qbRr7XHJnFm29kkJbTwkB4CJes6z8BhjUUZ\nSeHOV3zaWFaIV8cX9tvTtKb5l10I7QPVOHA+byV8QurHlvqL45nnVFbndjWf\nJOrnIEMe6fiOD0I9/0sLzrrTDNgFcBhU+ZKqo5aI2cwC8eps0nRsOf7JBJA7\ngJw7Hx1JuPGj20TppyRXn6CMJbq7Tgigiasnla0H+++O45kXws9JhdF3FX86\nnS2T\r\n=EXvb\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCpFh4GSpnXSXEs97Wf17vj68erB2bRnX2j9W6eDBBy2gIgKygqLKH8/SuyDG7kMpWuJnG/VWKOKqQCN7ZAi6kwgoI="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.1_1639382482457_0.3282577808711462"},"_hasShrinkwrap":false},"2.0.2":{"name":"ember-cli-content-security-policy","version":"2.0.2","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.26.3","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@ember/test-helpers":"^2.6.0","@embroider/test-setup":"^0.47.1","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.1.0","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.26.0","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-fastboot":"^3.2.0-beta.4","ember-cli-htmlbars":"^6.0.0","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-terser":"^4.0.1","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^1.0.0","ember-qunit":"^5.1.4","ember-resolver":"^8.0.2","ember-source":"~3.28.4","ember-source-channel-url":"^3.0.0","ember-try":"^2.0.0","eslint":"^7.23.0","eslint-config-prettier":"^8.1.0","eslint-plugin-ember":"^10.5.8","eslint-plugin-node":"^11.1.0","eslint-plugin-prettier":"^4.0.0","execa":"^5.1.1","fs-extra":"^10.0.0","loader.js":"^4.7.0","mocha":"^9.1.3","npm-run-all":"^4.1.5","prettier":"~2.5.0","qunit":"^2.14.1","qunit-dom":"^2.0.0","release-it":"^14.11.8","release-it-lerna-changelog":"^4.0.1","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"12.* || 14.* || >= 16"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"gitHead":"b048d2b206946efc498a116031786622f85f353d","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.2","_nodeVersion":"16.13.1","_npmVersion":"8.1.2","dist":{"integrity":"sha512-rrJVH0Y0suT+YikbcAcS0qp5YW/fXFANbA1bvo4WI+tuvp1yaBhzo08iuX5sgmE7ldeuVuiKpkwSfwoncFENSg==","shasum":"b99acf171a81c1d12395e669508bc18713797735","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.2.tgz","fileCount":18,"unpackedSize":542508,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhwG4vCRA9TVsSAnZWagAAK74P/j6L8nUbJr5578VzLqfQ\nMB7ebrt7UwV2sF+Ldu/0OnQPt+JKqGquNGpRkZN2KKuaXXNtZDjN4wF4yGKG\nSYpG5YOZBH/I/9p0vY2ETi2hJ+XMbzSE/lLxgt6P9E2DR9jUxkdbDhuup7FC\nWzUKz4aA9BCcB2O9FYqIEiq1szQCI4FPp4oeRTi9sTEI2qFNFhPjui2n2YkZ\nNDLANcxcXVWq+wssom3XbHVEUynhLjFfzBQO0k8hhV69sTzEYkVDWyejk5fX\nM02bFyEydOussaHqHpBXg9nIhqJuyQJyNTGN7RdSbM+JmoEuvyA844EKIJHJ\nRN92AdF1AjPkFzG0t0F4U+5fVZj4vVFNlyXQ4OKyz+ChW/no9u2tKqCDbffX\nPVkMdr2DqsYZiacOknNh5+9tY4Sg7WD/Q6UyIYuAuhF16pi6wh+yMTYZMbBn\nQ37lpxJkzhG+Zi4SReI7ftuHAyWpyW/dm5WRHe9uhM70xFSw0m61rtWyCYDH\nBSzz/IAvnDGp6FuzRBq871bgap2lm3S3zdB7FyaWdUU0Icana70d0eCusJgg\nuwsi4Dq/6Vm2vmakbyZKalPlvCfWhJP4vTASHsOkQSN3jkJG/gjxhBXoPyQT\nyDNgBZF57Zj2Uju8Mez0hur5k9ahP6FFOsKpXoHHkRwIXrwUwOKImvgL4gHy\nP/+q\r\n=4g+Y\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCbzPbq5HTyLatii11sYNuht8MBkeJWclFibA1aGLRijAIgESksYkoXJ3H6XUWMSIdCG0+9put1iu7+TXdqGKdJ2d4="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.2_1640001071556_0.48728382815533733"},"_hasShrinkwrap":false},"2.0.3":{"name":"ember-cli-content-security-policy","version":"2.0.3","description":"This addon adds the Content-Security-Policy header to response sent from the Ember CLI Express server.","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"license":"MIT","author":"","directories":{"doc":"doc","test":"tests"},"scripts":{"build":"ember build --environment=production","lint":"npm-run-all --aggregate-output --continue-on-error --parallel 'lint:!(fix)'","lint:hbs":"ember-template-lint .","lint:js":"eslint . --cache","lint:js:fix":"eslint . --fix","lint:hbs:fix":"ember-template-lint . --fix","start":"ember serve","test":"npm-run-all --aggregate-output --continue-on-error --parallel 'test:*'","test:ember":"ember test","test:node":"mocha node-tests/**/*-test.js"},"dependencies":{"body-parser":"^1.17.0","chalk":"^4.1.1","debug":"^4.3.1","ember-cli-babel":"^7.26.3","ember-cli-version-checker":"^5.0.2"},"devDependencies":{"@ember/optional-features":"^2.0.0","@ember/test-helpers":"^2.6.0","@embroider/test-setup":"^0.47.1","@glimmer/tracking":"^1.0.0","babel-eslint":"^10.1.0","broccoli-asset-rev":"^3.0.0","chai":"^4.3.0","denodeify":"^1.2.1","ember-addon-tests":"^0.0.2","ember-cli":"~3.26.0","ember-cli-addon-tests":"^0.11.1","ember-cli-dependency-checker":"^3.2.0","ember-cli-fastboot":"^3.2.0-beta.4","ember-cli-htmlbars":"^6.0.0","ember-cli-inject-live-reload":"^2.0.2","ember-cli-sri":"^2.1.1","ember-cli-template-lint":"^2.0.2","ember-cli-terser":"^4.0.1","ember-disable-prototype-extensions":"^1.1.3","ember-export-application-global":"^2.0.1","ember-load-initializers":"^2.1.2","ember-maybe-import-regenerator":"^1.0.0","ember-qunit":"^5.1.4","ember-resolver":"^8.0.2","ember-source":"~3.28.4","ember-source-channel-url":"^3.0.0","ember-try":"^2.0.0","eslint":"^7.23.0","eslint-config-prettier":"^8.1.0","eslint-plugin-ember":"^10.5.8","eslint-plugin-node":"^11.1.0","eslint-plugin-prettier":"^4.0.0","execa":"^5.1.1","fs-extra":"^10.0.0","loader.js":"^4.7.0","mocha":"^9.1.3","npm-run-all":"^4.1.5","prettier":"~2.5.0","qunit":"^2.14.1","qunit-dom":"^2.0.0","release-it":"^14.11.8","release-it-lerna-changelog":"^4.0.1","request":"^2.88.0","semver":"^7.3.5"},"engines":{"node":"12.* || 14.* || >= 16"},"publishConfig":{"registry":"https://registry.npmjs.org"},"ember":{"edition":"octane"},"ember-addon":{"configPath":"tests/dummy/config","before":["serve-files-middleware","broccoli-serve-files","history-support-middleware","proxy-server-middleware"]},"release-it":{"plugins":{"release-it-lerna-changelog":{"infile":"CHANGELOG.md","launchEditor":true}},"git":{"tagName":"v${version}"},"github":{"release":true,"tokenRef":"GITHUB_AUTH"}},"gitHead":"5c5920fe6a26fee5f58c01357d0c6f065f48bed9","bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","_id":"ember-cli-content-security-policy@2.0.3","_nodeVersion":"16.13.1","_npmVersion":"8.1.2","dist":{"integrity":"sha512-tSGRbR2XiOjHk7oEH7LVF1y5S643rUEjl3mujI6EYPkrQbHaV0WdLyIWJkLvuP1KGnjBfvnLCyiKDFu6z2PjVg==","shasum":"833eca6be4d625f8b1b85cf5bad62544b535b483","tarball":"https://registry.npmjs.org/ember-cli-content-security-policy/-/ember-cli-content-security-policy-2.0.3.tgz","fileCount":18,"unpackedSize":542817,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh0c9TCRA9TVsSAnZWagAATaEP/1How0ZRsgdqMYvWQWVH\nSeIwZGp+NcHPjwcIeNnfQ47Zl00xtvLpFIxSii5s6x4s7VEXFIBofyWhlQzK\nKxCAwrj9t2XXXBSBKnXYALpHe89Ys97756UxJRMsmzdKpkp/2VUpa7hLJNfH\n/iMMd+uy4FAWRGWZ1JmeJfDgzol6zOeAioUpbdTbOQd5gSBClt6+vEYgePqR\nJS3MUZ5wGAPCtr+JzqL4P4YqveZ2t9Gr71lpU6C9AoXv9Q8l3sZOYOz22EyC\n+m7ve218DA8ChZBifvgJRXt9+KG/IE8vCRuUOuYsU2ZFxT2p3IrQ5/DO3WvE\noV4X5Yj3UPNI3ZANCgQrV4M715WDRiCWP7BuDcxGdTFnNLKDL76KisEP+UQv\nfHlF4OSgKJehRgzZQjSU0zWGN0I9JpqJ9A1XSUKw+1JtoyAmHT5xqkXpIvMB\nw5Tagz8miwT/kIe/z6HUvu6xda1hY7XA7zWUgeLIF2HXpm9FDgBxrHadj7bp\nyHT/AtTm1dDvf6q98+ya8Y08rzVByosQafxPgxaDWcXzgeSFQC6LwjL5IjcG\nM6lBL5ImAihOy0Kdp6hAllMrhwPWY6x5fRNr+oio6jzwNgRLtQGycvSPs90A\n/+edz5nXULj4SzCqZIqLV0nWSegmWO5+ClQ4lCO7Sa70b4bXgv3OdQJDstgD\nqmid\r\n=Xxk2\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC0zYN6dgm257teg2O1B/8tTTgCNBL8OM+9k8AexBDjFwIgYDwRGaor/FrEp0AjwcBvaGN2zpi3Pe1hH9c8Ka4Nvmk="}]},"_npmUser":{"name":"jelhan","email":"npm@jhanschke.de"},"maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/ember-cli-content-security-policy_2.0.3_1641140051262_0.9521531345721519"},"_hasShrinkwrap":false}},"readme":"# ember-cli-content-security-policy\n\nThis addon makes it easy to use [Content Security Policy](https://content-security-policy.com/) (CSP) in your project. The policy can be delivered either via a `Content-Security-Policy` HTTP response header or as a meta tag in the `index.html` file.\n\nIf configured to deliver the CSP using a HTTP response header, the header is set automatically if served with Ember CLI's express server in development or via [FastBoot](https://ember-fastboot.com/) in production. If FastBoot is not used to serve the app in production, the web server must be configured to set the CSP header. The configured CSP could be exported with a provided Ember CLI command.\n\nIf configured to deliver the CSP using the meta tag no additional configuration of the web server serving the application in production is needed.\n\nIn any case, using this addon helps keeping CSP in the forefront of your thoughts while developing an Ember application.\n\n## Compatibility\n\n- Ember.js v2.18 or above\n- Ember CLI v3.4 or above\n- Node.js v12 or above\n\n## Installation\n\n```bash\nember install ember-cli-content-security-policy\n```\n\n## Configuration\n\nThis addon is configured via `config/content-security-policy.js` file.\n\n```ts\ntype directiveName =\n  // Fetch Directives\n  | 'child-src'\n  | 'connect-src'\n  | 'default-src'\n  | 'font-src'\n  | 'frame-src'\n  | 'image-src'\n  | 'manifest-src'\n  | 'media-src'\n  | 'object-src'\n  | 'prefetch-src'\n  | 'script-src'\n  | 'script-src-elem'\n  | 'script-src-attr'\n  | 'style-src'\n  | 'style-src-elem'\n  | 'style-src-attr'\n  | 'worker-src'\n  // Document Directives\n  | 'base-uri'\n  | 'plugin-types'\n  | 'sandbox'\n  // Navigation Directives\n  | 'form-action'\n  | 'frame-ancestors'\n  | 'navigate-to'\n  // Reporting Directives\n  | 'report-uri'\n  | 'report-to'\n  // Directives Defined in Other Documents\n  | 'block-all-mixed-content'\n  | 'upgrade-insecure-requests'\n  | 'require-sri-for';\n\ninterface EmberCLIContentSecurityPolicyConfig {\n  // CSP is delivered via HTTP Header if delivery includes `\"header\"` and via\n  // meta element if it includes `\"meta\"`.\n  delivery?: string;\n\n  // Controls if addon is enabled at all.\n  enabled?: boolean;\n\n  // Controls if addon causes tests to fail if they violate configured CSP\n  // policy.\n  failTests: true;\n\n  // A hash of options representing a Content Security Policy. The key must be\n  // a CSP directive name as defined by spec. The value must be an array of\n  // strings that form a CSP directive value, most likely a source list, e.g.\n  // {\n  //   'default-src': [\"'none'\"],\n  //   'style-src': [\"'self'\", 'examples.com']\n  // }\n  // Please refer to CSP specification for details on valid CSP directives:\n  // https://w3c.github.io/webappsec-csp/#framework-directives\n  policy?: {[key: directiveName]: string[]};\n\n  // Controls if CSP is used in report only mode. For delivery mode `\"header\"`\n  // this causes `Content-Security-Policy-Report-Only` HTTP header to be used.\n  // Can not be used together with delivery mode `\"meta\"` as this is not\n  // supported by CSP spec.\n  reportOnly?: boolean;\n}\n```\n\nIf you omit some or all of the keys, the default configuration will be used, which is:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['header'],\n    enabled: true,\n    failTests: true,\n    policy: {\n      'default-src': [\"'none'\"],\n      'script-src': [\"'self'\"],\n      'font-src': [\"'self'\"],\n      'connect-src': [\"'self'\"],\n      'img-src': [\"'self'\"],\n      'style-src': [\"'self'\"],\n      'media-src': [\"'self'\"],\n    },\n    reportOnly: true,\n  };\n};\n```\n\n> Keywords such as `self`, `none`, `unsafe-inline`, nonces and digests must be wrapped in single quotes (`'`) as shown above. Please find more details about valid source expression in [§ 2.3.1. Source Lists of CSP specification](https://www.w3.org/TR/CSP3/#framework-directive-source-list).\n\nChanges to the configuration require a restart of a running Ember development server instance.\n\n### Example\n\nIf your site uses **Google Fonts**, **Mixpanel**, a custom API at **custom-api.local** and you want to deliver the CSP using a meta element:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    delivery: ['meta'],\n    policy: {\n      // Deny everything by default\n      'default-src': [\"'none'\"],\n      // Allow scripts at https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js\n      'script-src': [\"'self'\", 'https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js'],\n      // Allow fonts to be loaded from http://fonts.gstatic.com\n      'font-src': [\"'self'\", 'http://fonts.gstatic.com'],\n      // Allow data (xhr/websocket) from api-js.mixpanel.com and custom-api.local\n      'connect-src': [\"'self'\", 'https://api-js.mixpanel.com', 'https://custom-api.local'],\n      // Allow images from the origin itself (i.e. current domain)\n      'img-src': [\"'self'\"],\n      // Allow CSS loaded from https://fonts.googleapis.com\n      'style-src': [\"'self'\", 'https://fonts.googleapis.com'],\n      // Omit `media-src` from policy\n      // Browser will fallback to default-src for media resources (which is 'none', see above)\n      'media-src': null,\n    },\n    reportOnly: false,\n  };\n};\n```\n\n## FastBoot Integration\n\nThis addon sets the CSP HTTP response header in FastBoot if it's enabled for the used environment and `delivery` contains `\"header\"`. It does not override existing CSP headers.\n\nIf using `reportOnly` mode you must provide a valid `reportUri` directive pointing to an endpoint that accepts violation reports. As `reportUri` directive is deprecated you should additionally provide a `reportTo` directive, even so it's only supported by Google Chrome so far.\n\nIf you don't want the addon to inject the CSP header in FastBoot on production (e.g. cause CSP header should be set by a reverse proxy in front of FastBoot App Server), you should either remove `\"header\"` from `delivery` option or disable the addon entirely.\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'production',\n    delivery: ['header'],\n  };\n};\n```\n\n## External Configuration\n\nIn order to configure your production web server, you can use the `csp-headers` Ember CLI command to obtain the configured Content Security Policy:\n\n```bash\n$ ember csp-headers --environment production --report-uri /csp-report\n\n# Content Security Policy Header Configuration\n#\n# for Apache: Header set Content-Security-Policy-Report-Only \"...\"\n# for Nginx : add_header Content-Security-Policy-Report-Only \"...\";\n\ndefault-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; report-uri /csp-report;\n```\n\n## Development Support\n\nEmber CLI's live reload feature requires a Web Socket connection. If live reload is used with `ember serve` or `ember test --server` the URL used for that Web Socket connection is injected into `connect-src` and `script-src` directives automatically.\n\n## Test Support\n\nThe addon helps you to ensure that your app or addon is compliant with a specific Content Security Policy by providing test support. It causes tests to fail if the code triggers a violation of the configured CSP.\n\nIt's recommended to test your project for CSP compliance. But you could disable it nevertheless by setting `enabled` option to `false` for `test` environment:\n\n```js\n// config/content-security-policy.js\n\nmodule.exports = function (environment) {\n  return {\n    enabled: environment !== 'test',\n  };\n};\n```\n\n## Compatibility with other addons\n\nSome addons are not compatible with a strict Content Security Policy. If you face any CSP violations caused by a third-party addon please report at their side. Often it's only a small change to required to make it compliant with a strict CSP. You may want to suggest adding this addon to test for compliance with a strict CSP.\n\nFor some addons compliance with a strict CSP requires a custom configuration. This documentation lists required configuration for some famous once. <!-- This docs should only include addons that are in Top 100 list provided by Ember Observer. -->\n\n### Ember Auto Import\n\n[Ember Auto Import](https://github.com/ef4/ember-auto-import#ember-auto-import) uses the `eval` function by default in development builds. This violates the default CSP policy. It's recommended to set Ember Auto Import's `forbidEval` option to `true` if using Content Security Policy. You should _not_ add `'unsafe-eval'` to `script-src` directive as this disalbes main security provided by CSP.\n\n### Embroider\n\n[Webpack](https://webpack.js.org/), which is used by [Embroider](https://github.com/embroider-build/embroider), uses the `eval` function by default in development builds to generate a source map. This violates the default CSP policy. It's recommended to configure Webpack to use [`'source-map'` strategy to generate source maps](https://webpack.js.org/configuration/devtool/). To do so, add the following Embroider configuration:\n\n```js\nreturn require('@embroider/compat').compatBuild(app, Webpack, {\n  packagerOptions: {\n    // other configuration\n    webpackConfig: {\n      devtool: 'source-map',\n    },\n  },\n});\n```\n\nFor addons using `maybeEmbroider` utility provided by `@embroider/test-setup` the configuration looks like this:\n\n```js\nconst { maybeEmbroider } = require('@embroider/test-setup');\nreturn maybeEmbroider(app, {\n  // other configuration\n  packagerOptions: {\n    webpackConfig: {\n      devtool: 'source-map',\n    },\n  },\n});\n```\n\n### ember-cli-code-coverage\n\nEmber-cli-code-coverage uses Istanbul, which injects `new Function('return this')` by default into the app. This requires `'unsafe-eval'` to be allowed by the script directive. Currently there isn't any other option than either adding `'unsafe-eval'` to script directive if code coverage is enabled or disable CSP at all. Details could be found in [this issue](https://github.com/kategengler/ember-cli-code-coverage/issues/214).\n\n## Deprecations\n\nPlease find detailed information about deprecations in [deprecation guide](DEPRECATIONS.md).\n","maintainers":[{"name":"rwjblue","email":"me@rwjblue.com"},{"name":"jelhan","email":"npm@jhanschke.de"}],"time":{"modified":"2022-06-16T20:36:36.743Z","created":"2014-09-21T02:16:59.827Z","0.1.0":"2014-09-21T02:16:59.827Z","0.1.1":"2014-09-22T17:08:20.551Z","0.1.2":"2014-09-29T17:30:56.831Z","0.1.3":"2014-09-30T12:30:39.219Z","0.1.4":"2014-10-03T12:02:29.808Z","0.2.0":"2014-10-04T21:02:16.507Z","0.2.1":"2014-10-06T21:12:09.191Z","0.3.0":"2014-10-13T22:05:26.755Z","0.4.0":"2015-03-13T01:31:07.636Z","0.5.0":"2016-01-18T21:43:27.781Z","0.6.0":"2017-01-31T14:03:03.828Z","0.6.1":"2017-04-03T15:34:03.786Z","0.6.2":"2017-07-28T16:21:00.718Z","1.0.0":"2017-08-15T14:02:30.472Z","1.1.0":"2019-02-19T17:13:58.131Z","1.1.1":"2019-02-20T21:50:50.527Z","2.0.0-0":"2020-04-13T09:24:34.864Z","2.0.0-1":"2020-04-15T07:12:13.983Z","2.0.0-2":"2021-01-09T17:43:04.298Z","2.0.0-3":"2021-04-16T18:55:14.577Z","2.0.0-4":"2021-05-06T14:24:22.839Z","2.0.0-5":"2021-10-28T23:10:40.279Z","2.0.0":"2021-11-12T15:26:59.871Z","2.0.1":"2021-12-13T08:01:22.852Z","2.0.2":"2021-12-20T11:51:11.793Z","2.0.3":"2022-01-02T16:14:11.472Z"},"homepage":"https://github.com/rwjblue/ember-cli-content-security-policy#readme","keywords":["ember-addon"],"repository":{"type":"git","url":"git+https://github.com/rwjblue/ember-cli-content-security-policy.git"},"bugs":{"url":"https://github.com/rwjblue/ember-cli-content-security-policy/issues"},"license":"MIT","readmeFilename":"README.md","users":{"prule":true}}