Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Csp Builder Laravel Package

paragonie/csp-builder

Build and send Content-Security-Policy headers in PHP from JSON files, JSON strings, or arrays. CSP Builder makes it easy to define directives programmatically and integrate CSP into web apps to improve security.

View on GitHub
Deep Wiki
Context7
v3.0.1
  • #77 - prevent duplicate policies
  • Updated dependencies
v3.0.0

What's Changed

Full Changelog: https://github.com/paragonie/csp-builder/compare/v2.9.0...v3.0.0

v2.9.0

What's Changed

New Contributors

Full Changelog: https://github.com/paragonie/csp-builder/compare/v2.8.1...v2.9.0

v2.8.1

What's Changed

New Contributors

Full Changelog: https://github.com/paragonie/csp-builder/compare/v2.8.0...v2.8.1

v2.8.0

Prevent semicolon or CLRF injection. See https://github.com/paragonie/csp-builder/commit/1a1a85fcf115400d7753af842403ec6e846319de for details.

CSP-Builder is a developer tool. It is not meant to be used with user input.

However, the ability to inject CSP directives or additional headers violates the principle of least astonishment.

This was reported via user demonia on HackerOne.

v2.7.0
  • CI: Build/test on PHP 8.2
  • Add support for "unsafe-hashes" directive
v2.6.0
  • #56 You can now save policies as JSON strings or to disk (reported in #39)
  • #55 Allow hooks before writing output to disk
  • #54 Allow https: scheme sources
  • #51 Allow sample report directive
  • Fixed #23 -- duplicate directives are now prevented
  • Implemented #52
v2.5.0
  • Consistently invalidate the compiled CSP cache.
  • Update PHPUnit, etc.
  • Dropped support for PHP 7.0. You can continue to install 2.4.0, but we will not be backporting patches into the old version. PHP 7.0 is EOL, please upgrade to 7.4 or newer.
v2.4.0
  • #42 - In Chrome 76, this library's behavior with report-to does not work. Specifically, you cannot pass a URL as a report-to directive or Chrome will never send CSP reports, even if there is also a report-uri fallback. @iangcarroll provided a pull request that fixes this behavior.
v2.3.0
  • #21 - Add always clause to nginx header. Thanks @alainwolf
  • #17 - Add support for blob:, filesystem:, and data: URIs.
  • Added CSPBuilder::fromArray() because its absence seemed confusing if you're not familiar with the constructor.
  • Minor documentation improvements. Not nearly enough to close #18, though.
v2.2.0
  • Add dedicated API method for setting report-to/report-uri directives.
  • Add support for 'strict-dynamic' and 'unsafe-hashed-attributes'
v1.4.0

Contains a year of bugfixes and tweaks from the v2 branch, backported for PHP 5 support.

v2.1.0
  • Added several helper methods, e.g. setDataAllowed() and setSelfAllowed(), for programatically allowing self and data: URIs for a specific directive.
  • CSP-Builder is now type-safe! This can be verified by Psalm. In future releases, this will be enforced by Travis CI.
  • Docblock and unit test cleanup.
v2.0.1

Allow CSPBuilder instances to be instantiated from a JSON string. Thanks [@renanmpimentel](https://github.com/renanmpimentel)

v1.3.3

Version 1.3.2 broke somewhere in the git chain, so v1.3.3 it is.

v2.0.0

Version 2.0.0 requires PHP 7.

This allows us to use strict typing and drop random_compat as a dependency.

v1.3.1
  • Minor (some annoying) bug fixes
  • Fix whitespace in unsafe-eval directives

Full list here: https://github.com/paragonie/csp-builder/compare/v1.3.0...v1.3.1

v1.3.0

A lot of bugfixes since 1.2.0.

BC break: Changed our erroneous connect-uri and font-uri directives to connect-src and font-src respectively.

Before version 1.4, I'd like to improve the documentation and unit test coverage. Feel free to open any issues for bugs you encounter or feature requests you might have.

v1.2.4

Use normal Base64 encoding for CSP hashes.

v1.2.3

It turns out that the hash directive just needs to be sha256-blah not hash-sha256-blah.

v1.2.2

Add preHash(), which allows users to precalculate a hash of a resource and store it directly in the CSP. (Mostly useful for locally caching the hashes of remote resources.)

v1.2.1
  • Fix hash()
  • Confirmed that CSP headers work as expected with report-uri.io
v1.2.0
  • BC break: Adopted random_compat instead of openssl for generating a nonce
  • BC break: Established PHP 5.5 as the minimum version. Previously, this was undefined.
  • Added method for getting the headers as an array (see #5)
  • Added method to inject headers into a PSR-7 message (see #5)
  • Added support for the plugin-types directive (see #4)

Thanks @Ocramius and @Lewiscowles1986 for their feedback and assistance. (If it weren't for the possibly BC-breaking changes, this would have simply been 1.1.1.)

v1.1.0

General improvements, especially with older Webkit browsers.

Thanks to @timoh6 and @ScottHelme for their feedback.

v1.0.0

Initial release.

Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
codifyo/ts-generator-bundle
andydefer/laravel-cluster
testo/fiber
mintobit/jobqueue
a4sex/maintenance-bundle
a4sex/entity-date-update
a4sex/client-identifier
a4sex/base-utilites
a4sex/key-value-storage
a4sex/micro-status
chilldev/dependency-injection-extra
datinglibre/datinglibre-app-api
biberltd/corebundle
bricre/symfony-bundle-test
biberltd/logbundle
dominium/http-adapter-bundle
dominium/google-analytics
a4sex/auto-clean-entity
christhompsontldr/laravel-inky
spatie/mailcoach-vapor