{"_id":"vite-plugin-content-security-policy","_rev":"6-2deec0bd84d0b56892b8c420a103f1b1","name":"vite-plugin-content-security-policy","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"vite-plugin-content-security-policy","version":"1.0.0","keywords":["vite","vite-plugin","content-security-policy","csp","security","headers","apache","nginx"],"author":{"url":"https://coreoz.com","name":"Aurélien Manteaux","email":"amanteaux@coreoz.com"},"license":"Apache-2.0","_id":"vite-plugin-content-security-policy@1.0.0","maintainers":[{"name":"vincentdbs","email":"vincent.dubois@efrei.net"}],"contributors":[{"name":"Vincent Dubois"}],"homepage":"https://github.com/Coreoz/vite-plugin-content-security-policy#readme","bugs":{"url":"https://github.com/Coreoz/vite-plugin-content-security-policy/issues"},"dist":{"shasum":"6f3115ba87826008fb8a7182b0b2cc6fd60625ed","tarball":"https://registry.npmjs.org/vite-plugin-content-security-policy/-/vite-plugin-content-security-policy-1.0.0.tgz","fileCount":20,"integrity":"sha512-o0H52ugQtu9XZiqu+5/vI4DZlhJi7q+b8zP65VK20swoopIEQYWTf3XpSP0rlAtUe1kGDuI4UIl+CMviccaI8w==","signatures":[{"sig":"MEQCIFozPqpDBBJ2hkqejvy1i7lhfQpcZGVuDByegZVfZBmTAiAk7irTS9ilWZf07NaCFtPjHLvh48AQWM2x33zHpICOEQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":174663},"main":"build/index.js","type":"module","module":"build/index.js","engines":{"node":">=18"},"gitHead":"81e8a38967019f1ed0d5ade039594c7e4a983756","scripts":{"test":"vitest run","build":"tsc -p tsconfig.app.json && tsc-alias -p tsconfig.app.json","clean":"rm -rf build","eslint":"eslint src --ext .ts","release":"release-it","typescript":"tsc --noEmit -p tsconfig.json","prepare-release":"yarn clean && yarn typescript && yarn eslint && yarn test && yarn build"},"typings":"build/index.d.ts","_npmUser":{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},"release-it":{"hooks":{"before:init":["yarn prepare-release"]}},"repository":{"url":"git+https://github.com/Coreoz/vite-plugin-content-security-policy.git","type":"git"},"_npmVersion":"10.9.2","description":"A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files","directories":{},"_nodeVersion":"22.14.0","dependencies":{"simple-logging-system":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"yarn@4.12.0","devDependencies":{"vite":"^7.3.1","eslint":"^9.38.0","vitest":"^4.0.17","tsc-alias":"^1.8.16","release-it":"^19.2.4","typescript":"^5.9.3","@types/node":"^22.13.16","@types/eslint":"^9.6.1","@vitest/runner":"^4.0.17","@vitest/coverage-v8":"^4.0.17","eslint-plugin-compat":"^6.0.2","eslint-plugin-import":"^2.31.0","@sayari/eslint-plugin":"^0.0.1-rc.4","@stylistic/eslint-plugin":"^4.2.0","@typescript-eslint/parser":"^8.29.0","eslint-config-airbnb-base":"^15.0.0","eslint-config-airbnb-typescript":"^18.0.0","eslint-plugin-typescript-compat":"^0.3.1","@typescript-eslint/eslint-plugin":"^8.29.0"},"_npmOperationalInternal":{"tmp":"tmp/vite-plugin-content-security-policy_1.0.0_1769157555145_0.030506252380791077","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"vite-plugin-content-security-policy","version":"1.0.1","keywords":["vite","vite-plugin","content-security-policy","csp","security","headers","apache","nginx"],"author":{"url":"https://coreoz.com","name":"Aurélien Manteaux","email":"amanteaux@coreoz.com"},"license":"Apache-2.0","_id":"vite-plugin-content-security-policy@1.0.1","maintainers":[{"name":"benoitvasseur","email":"bvasseur@coreoz.com"},{"name":"amanteaux","email":"amanteaux@gmail.com"},{"name":"lucas-amiaud","email":"lamiaud@coreoz.com"},{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},{"name":"mlecorvec","email":"mlecorvec@coreoz.com"}],"contributors":[{"name":"Vincent Dubois"}],"homepage":"https://github.com/Coreoz/vite-plugin-content-security-policy#readme","bugs":{"url":"https://github.com/Coreoz/vite-plugin-content-security-policy/issues"},"dist":{"shasum":"4aacb00dbc1301e001121c3a8135323a689b8d9f","tarball":"https://registry.npmjs.org/vite-plugin-content-security-policy/-/vite-plugin-content-security-policy-1.0.1.tgz","fileCount":20,"integrity":"sha512-P9aChbK8aYxB2NDATB5mmeY5SjAhuQ07V4XWIYQ+26YP6wKaTGmGDkzIkrkRf/x4Du7I+ffeTCNCx6dOz22EaQ==","signatures":[{"sig":"MEQCIDs279H9ZFGvfEdPGanQnJ0VXRIANIjvhp9JjrEaMfC6AiBRj1nHFk7fNfeS2QnGDmStkaCd2YNrgOADUNuNz2Idkg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":174756},"main":"build/index.js","type":"module","module":"build/index.js","engines":{"node":">=18"},"gitHead":"099eace7274ad5547908d354be44ded345ceefd7","scripts":{"test":"vitest run","build":"tsc -p tsconfig.app.json && tsc-alias -p tsconfig.app.json --resolve-full-paths","clean":"rm -rf build","eslint":"eslint src --ext .ts","release":"release-it","typescript":"tsc --noEmit -p tsconfig.json","prepare-release":"yarn clean && yarn typescript && yarn eslint && yarn test && yarn build"},"typings":"build/index.d.ts","_npmUser":{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},"release-it":{"hooks":{"before:init":["yarn prepare-release"]}},"repository":{"url":"git+https://github.com/Coreoz/vite-plugin-content-security-policy.git","type":"git"},"_npmVersion":"10.9.2","description":"A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files","directories":{},"_nodeVersion":"22.14.0","dependencies":{"simple-logging-system":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"yarn@4.12.0","devDependencies":{"vite":"^7.3.1","eslint":"^9.38.0","vitest":"^4.0.17","tsc-alias":"^1.8.16","release-it":"^19.2.4","typescript":"^5.9.3","@types/node":"^22.13.16","@types/eslint":"^9.6.1","@vitest/runner":"^4.0.17","@vitest/coverage-v8":"^4.0.17","eslint-plugin-compat":"^6.0.2","eslint-plugin-import":"^2.31.0","@sayari/eslint-plugin":"^0.0.1-rc.4","@stylistic/eslint-plugin":"^4.2.0","@typescript-eslint/parser":"^8.29.0","eslint-config-airbnb-base":"^15.0.0","eslint-config-airbnb-typescript":"^18.0.0","eslint-plugin-typescript-compat":"^0.3.1","@typescript-eslint/eslint-plugin":"^8.29.0"},"_npmOperationalInternal":{"tmp":"tmp/vite-plugin-content-security-policy_1.0.1_1769161254394_0.5933367568026933","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"vite-plugin-content-security-policy","version":"1.0.2","keywords":["vite","vite-plugin","content-security-policy","csp","security","headers","apache","nginx"],"author":{"url":"https://coreoz.com","name":"Aurélien Manteaux","email":"amanteaux@coreoz.com"},"license":"Apache-2.0","_id":"vite-plugin-content-security-policy@1.0.2","maintainers":[{"name":"benoitvasseur","email":"bvasseur@coreoz.com"},{"name":"amanteaux","email":"amanteaux@gmail.com"},{"name":"lucas-amiaud","email":"lamiaud@coreoz.com"},{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},{"name":"mlecorvec","email":"mlecorvec@coreoz.com"}],"contributors":[{"name":"Vincent Dubois"}],"homepage":"https://github.com/Coreoz/vite-plugin-content-security-policy#readme","bugs":{"url":"https://github.com/Coreoz/vite-plugin-content-security-policy/issues"},"dist":{"shasum":"de1deec51daee7f10dfa6afe9e5375323b4ca40d","tarball":"https://registry.npmjs.org/vite-plugin-content-security-policy/-/vite-plugin-content-security-policy-1.0.2.tgz","fileCount":20,"integrity":"sha512-cgntSi9SjmAncM8PNnH3mSEo2d6ytNzPcAIdomKHsTFXfO1dDObP4WRYjcdUMoiZ0YJDuFWrk3KpOTGzeSNq/w==","signatures":[{"sig":"MEUCIQD0LerJtxzOaR7dxuV4fEyFX4A16OiVfbzi+kqseUT4xgIgI63a6ZJPWVvuhCmVcTeOdH3XY9k6MZ99knpuF0w/nQY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":176420},"main":"build/index.js","type":"module","module":"build/index.js","engines":{"node":">=18"},"gitHead":"ee57e1b0af71735f9d176041f481c215b54aa3bf","scripts":{"test":"vitest run","build":"tsc -p tsconfig.app.json && tsc-alias -p tsconfig.app.json --resolve-full-paths","clean":"rm -rf build","eslint":"eslint src --ext .ts","release":"release-it","typescript":"tsc --noEmit -p tsconfig.json","prepare-release":"yarn clean && yarn typescript && yarn eslint && yarn test && yarn build"},"typings":"build/index.d.ts","_npmUser":{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},"release-it":{"hooks":{"before:init":["yarn prepare-release"]}},"repository":{"url":"git+https://github.com/Coreoz/vite-plugin-content-security-policy.git","type":"git"},"_npmVersion":"10.9.2","description":"A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files","directories":{},"_nodeVersion":"22.14.0","dependencies":{"simple-logging-system":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"yarn@4.12.0","devDependencies":{"vite":"^7.3.1","eslint":"^9.38.0","vitest":"^4.0.17","tsc-alias":"^1.8.16","release-it":"^19.2.4","typescript":"^5.9.3","@types/node":"^22.13.16","@types/eslint":"^9.6.1","@vitest/runner":"^4.0.17","@vitest/coverage-v8":"^4.0.17","eslint-plugin-compat":"^6.0.2","eslint-plugin-import":"^2.31.0","@sayari/eslint-plugin":"^0.0.1-rc.4","@stylistic/eslint-plugin":"^4.2.0","@typescript-eslint/parser":"^8.29.0","eslint-config-airbnb-base":"^15.0.0","eslint-config-airbnb-typescript":"^18.0.0","eslint-plugin-typescript-compat":"^0.3.1","@typescript-eslint/eslint-plugin":"^8.29.0"},"_npmOperationalInternal":{"tmp":"tmp/vite-plugin-content-security-policy_1.0.2_1773836198889_0.24919051931547576","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"vite-plugin-content-security-policy","version":"1.0.3","description":"A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files","author":{"name":"Aurélien Manteaux","email":"amanteaux@coreoz.com","url":"https://coreoz.com"},"contributors":[{"name":"Vincent Dubois"}],"type":"module","main":"build/index.js","module":"build/index.js","typings":"build/index.d.ts","keywords":["vite","vite-plugin","content-security-policy","csp","security","headers","apache","nginx"],"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/Coreoz/vite-plugin-content-security-policy.git"},"homepage":"https://github.com/Coreoz/vite-plugin-content-security-policy#readme","bugs":{"url":"https://github.com/Coreoz/vite-plugin-content-security-policy/issues"},"publishConfig":{"access":"public"},"dependencies":{"simple-logging-system":"^1.1.0"},"devDependencies":{"@sayari/eslint-plugin":"^0.0.1-rc.4","@stylistic/eslint-plugin":"^4.2.0","@types/eslint":"^9.6.1","@types/node":"^22.13.16","@typescript-eslint/eslint-plugin":"^8.29.0","@typescript-eslint/parser":"^8.29.0","@vitest/coverage-v8":"^4.0.17","@vitest/runner":"^4.0.17","eslint":"^9.38.0","eslint-config-airbnb-base":"^15.0.0","eslint-config-airbnb-typescript":"^18.0.0","eslint-plugin-compat":"^6.0.2","eslint-plugin-import":"^2.31.0","eslint-plugin-typescript-compat":"^0.3.1","release-it":"^19.2.4","tsc-alias":"^1.8.16","typescript":"^5.9.3","vite":"^7.3.1","vitest":"^4.0.17"},"scripts":{"build":"tsc -p tsconfig.app.json && tsc-alias -p tsconfig.app.json --resolve-full-paths","clean":"rm -rf build","typescript":"tsc --noEmit -p tsconfig.json","eslint":"eslint src --ext .ts","prepare-release":"yarn clean && yarn typescript && yarn eslint && yarn test && yarn build","release":"release-it","test":"vitest run"},"release-it":{"hooks":{"before:init":["yarn prepare-release"]}},"packageManager":"yarn@4.12.0","engines":{"node":">=18"},"_id":"vite-plugin-content-security-policy@1.0.3","gitHead":"2b3980309ca35d7b02960500967562caa01f0e7f","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-JUmzrD6dpdDPj6siuwmivuJED1mU8xdEeYW1JPC5XW4HR181P6F38jbtTBhmJrpv/vZVXZF1mmClG+OPBFP5AA==","shasum":"e90bc9152d861e7d6435cb43155fa07a981b1f4b","tarball":"https://registry.npmjs.org/vite-plugin-content-security-policy/-/vite-plugin-content-security-policy-1.0.3.tgz","fileCount":20,"unpackedSize":176434,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD9pbGScUTGwZIjwieJ2n0IF+pedbMFC5gfwgDsjl/ovAIhAMJnT2Zw6J4uhp2b5SUWwVcJYQidn5z2Fw2JXFduMqA1"}]},"_npmUser":{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},"directories":{},"maintainers":[{"name":"benoitvasseur","email":"bvasseur@coreoz.com"},{"name":"amanteaux","email":"amanteaux@gmail.com"},{"name":"lucas-amiaud","email":"lamiaud@coreoz.com"},{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},{"name":"mlecorvec","email":"mlecorvec@coreoz.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vite-plugin-content-security-policy_1.0.3_1776937758417_0.2466997524515009"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-23T08:39:15.012Z","modified":"2026-04-23T09:49:18.798Z","1.0.0":"2026-01-23T08:39:15.343Z","1.0.1":"2026-01-23T09:40:54.529Z","1.0.2":"2026-03-18T12:16:39.026Z","1.0.3":"2026-04-23T09:49:18.610Z"},"bugs":{"url":"https://github.com/Coreoz/vite-plugin-content-security-policy/issues"},"author":{"name":"Aurélien Manteaux","email":"amanteaux@coreoz.com","url":"https://coreoz.com"},"license":"Apache-2.0","homepage":"https://github.com/Coreoz/vite-plugin-content-security-policy#readme","keywords":["vite","vite-plugin","content-security-policy","csp","security","headers","apache","nginx"],"repository":{"type":"git","url":"git+https://github.com/Coreoz/vite-plugin-content-security-policy.git"},"description":"A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files","contributors":[{"name":"Vincent Dubois"}],"maintainers":[{"name":"benoitvasseur","email":"bvasseur@coreoz.com"},{"name":"amanteaux","email":"amanteaux@gmail.com"},{"name":"lucas-amiaud","email":"lamiaud@coreoz.com"},{"name":"vincentdbs","email":"vincent.dubois@efrei.net"},{"name":"mlecorvec","email":"mlecorvec@coreoz.com"}],"readme":"# Vite Plugin Content Security Policy\n\nA Vite plugin for managing Content Security Policy (CSP) headers during development and generating\nApache/Nginx configuration files for production environments.\n\n## Features\n\nThis library provides two Vite plugins to help you manage Content Security Policy (CSP) in your web\napplications:\n\n1. **CSP Proxy Plugin**: Adds CSP headers to responses during development, allowing you to test your\n   application with CSP restrictions in place.\n2. **CSP Configuration File Generation Plugin**: Generates CSP configuration files for different\n   environments (production, staging, etc.) that can be used with Nginx or Apache servers.\n\n## Installation\n\n### Requirements\n\nThis package is an ESM package, be sure that your project is compatible with ESM.\nIn you are using a [Plume front project](https://github.com/Coreoz/create-plume-react-project) version <= 3.X.X, update your project to plume >= 4.X.X by following the [migration guide](https://github.com/Coreoz/create-plume-react-project/blob/master/docs/migration-guide-to-swc-plugin.md).\n\n### Adding the package to a project\n\n```bash\n# npm\nnpm install vite-plugin-content-security-policy --save-dev\n\n# yarn\nyarn add vite-plugin-content-security-policy --dev\n\n# pnpm\npnpm add vite-plugin-content-security-policy -D\n```\n\n## Usage\n\n### CSP Proxy Plugin\n\nThe CSP Proxy Plugin adds Content Security Policy headers to responses during development, allowing\nyou to test your application with CSP restrictions in place.\n\n```typescript\n// vite.config.ts\nimport { defineConfig } from 'vite';\nimport { cspProxyPlugin } from 'vite-plugin-content-security-policy';\n\n// Define your environments\nexport const ENVIRONMENTS = <const>['production', 'staging', 'development'];\nexport type Environment = typeof ENVIRONMENTS[number];\n\nexport default defineConfig({\n  plugins: [\n    cspProxyPlugin<Environment>({\n      // Optional: tell which configuration to apply when running vite serve (default is used if undefined) \n      developmentKey: 'development', \n      rules: {\n        'default-src': \"'self'\",\n        'script-src': \"'self'\",\n        'style-src': \"'self'\",\n        'img-src': \"'self' data:\",\n        'connect-src': \"'self' https://api.example.com\",\n      },\n      // Optional: Use 'report' for report-only mode, 'strict' for enforcement (default)\n      reportType: 'strict',\n    }),\n  ],\n});\n```\n\n### CSP Configuration File Generation Plugin\n\nThe CSP Configuration File Generation Plugin generates CSP configuration files for different\nenvironments that can be used with Nginx or Apache servers. File will be generated when the server starts.\n\n```typescript\n// vite.config.ts\nimport { defineConfig } from 'vite';\nimport { cspConfigurationFileGenerationPlugin } from 'vite-plugin-content-security-policy';\n\n// Define your environments\nexport const ENVIRONMENTS = <const>['production', 'staging', 'development'];\nexport type Environment = typeof ENVIRONMENTS[number];\n\nexport default defineConfig({\n  plugins: [\n    cspConfigurationFileGenerationPlugin<Environment>({\n      rules: {\n        'default-src': \"'self'\",\n        'script-src': {\n          default: \"'self'\",\n          production: \"'self' https://production.example.com\",\n          staging: \"'self' https://staging.example.com\",\n        },\n        'style-src': \"'self'\",\n        'img-src': \"'self' data:\",\n        'connect-src': {\n          default: \"'self'\",\n          production: \"'self' https://api.production.example.com\",\n          staging: \"'self' https://api.staging.example.com\",\n        },\n      },\n      environments: new Set(ENVIRONMENTS),\n      // Optional: Use 'report' for report-only mode, 'strict' for enforcement (default)\n      reportType: 'strict',\n      // Optional: Custom path for the CSP configuration file relatively to the root of the project\n      cspConfigurationFilePath: 'custom/path/csp-configuration.ts',\n    }),\n  ],\n});\n```\n\nThe plugin will generate configuration files in the `/content-security-policy/configurations`\ndirectory with names like `csp-configuration.production.txt`, `csp-configuration.staging.txt`, etc.\n\nEach file will contain configuration for both Nginx and Apache servers:\n\n```\n# Nginx configuration\nadd_header Content-Security-Policy \"default-src 'self'; script-src 'self' https://production.example.com; style-src 'self'; img-src 'self' data:; connect-src 'self' https://api.production.example.com\";\n\n# Apache configuration\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'self' https://production.example.com; style-src 'self'; img-src 'self' data:; connect-src 'self' https://api.production.example.com\"\n```\n> Note : File will be generated if vite.config.ts or if `/<root>/content-security-policy/csp-configuration.ts` change\n\n## Advanced Configuration\n\n### Report-Only Mode\n\nYou can use report-only mode to monitor CSP violations without blocking content:\n\n```typescript\ncspProxyPlugin<Environment>({\n  rules: {\n    // Your CSP rules\n  },\n  reportType: 'report',\n})\n```\n\nThis will use the `Content-Security-Policy-Report-Only` header instead of `Content-Security-Policy`.\n\n### Custom Configuration File Path\n\nYou can specify a custom path for the generated configuration files:\n\n```typescript\ncspConfigurationFileGenerationPlugin({\n  // Your CSP rules and environments\n  cspConfigurationFilePath: 'custom/path/csp-configuration.ts',\n})\n```\n\nConfiguration files will be generated when this file (or when vite.config.ts) changes.\n\n### Using Nonces with CSP\n\nYou can use nonces with CSP to allow specific inline scripts and styles. The plugin supports replacing a `{RANDOM}` placeholder with a generated nonce:\n\n1. Configure `html.cspNonce` in your Vite config:\n\n```typescript\n// vite.config.ts\nimport { defineConfig } from 'vite';\nimport { cspProxyPlugin } from 'vite-plugin-content-security-policy';\n\n// Define your environments\nexport const ENVIRONMENTS = <const>['production', 'staging', 'development'];\nexport type Environment = typeof ENVIRONMENTS[number];\n\nexport default defineConfig({\n  plugins: [\n    cspProxyPlugin<Environment>({ \n      developmentKey: 'development',\n      rules: {\n        'default-src': \"'self'\",\n        'script-src': \"'self' 'unsafe-inline' nonce-{RANDOM}\",\n        'style-src': \"'self' 'unsafe-inline' nonce-{RANDOM}\",\n      },\n      noncesConfiguration: {\n        template: '{RANDOM}', \n      }\n    }),\n  ],\n  html: {\n    cspNonce: '{RANDOM}',\n  },\n});\n```\n\n2. The plugin will:\n   - Generate a cryptographically secure random nonce\n   - Replace the `html.cspNonce` from the vite.config.ts with the generated nonce\n   - Replace `nonce-{RANDOM}` in CSP rules with `nonce-[generated-nonce]`\n\n> ⚠️ `html.cspNonce` from the vite.config.ts will be overridden by the plugin in development mode\n\nThis ensures that the same nonce is used for both the CSP headers and the HTML attributes, allowing specific inline scripts and styles to be executed while maintaining security.\n\n#### Apache\n\nIf you are using nonces with an Apache server :\n- add `<!--#echo var='CSP_NONCE' -->` in `html.cspNonce` property of `vite.config.ts`\n- enable SSI module and [csp nonce module](https://github.com/wyday/mod_cspnonce) in Apache\n\n## Resources\n\nSee [MDN documentation](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy#directives) for more information about CSP","readmeFilename":"README.md"}