Skip to main content

Flask-SecurityTxt

release pypi develop master gitlab github

Flask-SecurityTxt Logo

Flask-SecurityTxt is a simple extension for Flask that makes it easy to add a security.txt file to your website. This file, as specified by the Internet Security Research Group, is used to provide information to security researchers about how to report vulnerabilities in your website.

The Flask-SecurityTxt logo makes use of the cloud-lock-outline icon created by Michael Richins as part of the Material Design Icons (MDI) library and published through Pictogrammers under the Apache License 2.0.

Installation

You can install Flask-SecurityTxt using pip:

pip install Flask-SecurityTxt

Usage

from flask import Flask
from flask_security_txt import SecurityTxt

app = Flask(__name__)
security_txt = SecurityTxt(app)

You can also customize the contents of the security.txt file by providing the following settings in the configuration file:

Property Type Default Description
SECURITY_TXT_ENDPOINT str "security_txt" The name by which the end-point will be known to the Flask-app.
WELL_KNOWN_DIR str ".well-known" The name of the directory that will contain the security.txt file.
SECURITY_TXT_FILE_NAME str "security.txt" The name of the security.txt file.
SECURITY_TXT_SIGN_KEY str None The path to a file containing a PGP key used for signing the security.txt file.
SECURITY_TXT_CONTACT str Iterable None The value of the Contact field. An Iterable type value will result in multiple Contact fields. If None, the value is automatically generated from SECURITY_TXT_CONTACT_MAILBOX.
SECURITY_TXT_CONTACT_MAILBOX str "security" The local part of the automatically generated Contact email address. Only used if SECURITY_TXT_CONTACT is None.
SECURITY_TXT_EXPIRES str datetime None The value of the Expires field. A str type value is parsed into a datetime using dateutil; an unparseable string raises a ValueError. A datetime type value is formatted as an ISO 8601 timestamp with microseconds stripped. If None, the value is automatically generated using SECURITY_TXT_EXPIRES_OFFSET.
SECURITY_TXT_EXPIRES_OFFSET tuple timedelta (0, 0, 0, 0, 0, 0, 1) The offset applied to datetime.now() to automatically generate the Expires field value. A tuple is unpacked and passed to the timedelta constructor, which interprets the values as days, seconds, microseconds, milliseconds, minutes, hours, and weeks.
SECURITY_TXT_ENCRYPTION str Iterable None The value of the Encryption field. An Iterable type value will result in multiple Encryption fields. A value of None will omit the field entirely.
SECURITY_TXT_ACKNOWLEDGEMENTS str Iterable None The value of the Acknowledgments field. An Iterable type value will result in multiple Acknowledgments fields. A value of None will omit the field entirely.
SECURITY_TXT_PREFERRED_LANGUAGES str Iterable None The value of the Preferred-Languages field. An Iterable type value will result in a comma-separated string. If None, the value falls back to the translations listed by the Flask-Babel extension if it is loaded, or "en" otherwise.
SECURITY_TXT_CANONICAL str None The value of the Canonical field. If None, the value is resolved from the endpoint name in SECURITY_TXT_ENDPOINT using url_for. A value of None with no resolvable endpoint will omit the field.
SECURITY_TXT_POLICY str Iterable None The value of the Policy field. An Iterable type value will result in multiple Policy fields. A value of None will omit the field entirely.
SECURITY_TXT_HIRING str Iterable None The value of the Hiring field. An Iterable type value will result in multiple Hiring fields. A value of None will omit the field entirely.
SECURITY_TXT_FIELD_CASE str "standard" Controls the casing of field names in the output. Accepted values are "standard" (title case, e.g. Contact:), "lower" (e.g. contact:), and "upper" (e.g. CONTACT:).
SECURITY_TXT_HEADER str None A comment block prepended to the security.txt. Set to None to omit the header entirely.
SECURITY_TXT_FOOTER str A comment block appended to the security.txt. The default footer includes the Flask-SecurityTxt version and project links. Set to None to omit the footer entirely.

Configuring Comments

For each field, a comment can be added on the line immediately preceding it by setting a config key of the form SECURITY_TXT_<FIELD>_COMMENT, where <FIELD> is the upper-case field name (e.g. SECURITY_TXT_CONTACT_COMMENT, SECURITY_TXT_EXPIRES_COMMENT). It is up to the developer to prepend each line of the comment with a # and add any desired whitespace.

Configuring Contact Details

The Contact field of the security.txt file can be configured with one of two different ways. First of all, the whole value string can be defined using the SECURITY_TXT_CONTACT property. This takes precedence over the alternative method, which uses the SECURITY_TXT_CONTACT_MAILBOX property. The value of this property is combined with the domain name of the current host, as it is known to Flask. The latter method is less reliable, as such the prior method is preferred if possible. By default, the contact is set to be "security@

Example

A security.txt file will be available in your website's .well-known directory, with the following contents:

Contact: mailto:security@example.com
Encryption: https://example.com/key.asc
Canonical: https://example.com/.well-known/security.txt

Contributing

Found a bug? Have a suggestion? Open an issue or submit a merge request at the Forgejo repository. All contributions are welcome.

Metadata

Release files for Flask-SecurityTxt 1.3.11

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for Flask-SecurityTxt 1.3.11
File Size Uploaded
flask_securitytxt-1.3.11.tar.gz 22.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for Flask-SecurityTxt 1.3.11
File Interpreter ABI Platform
flask_securitytxt-1.3.11-py3-none-any.whl Python 3 none any Details

Total release size: 42.2 kB

Release files / flask_securitytxt-1.3.11.tar.gz

Download URL flask_securitytxt-1.3.11.tar.gz
Size 22.5 kB
Tags Source
SHA-256 checksum
How to use checksums
9a1476d6749f72bcc3e59e0096645994d97252295584e533f63de84ed1c640d6
BLAKE2b-256 checksum
How to use checksums
f5b04e8b2d34995c41abb0ab2fa404680a2c4b14cc4be31350de29c14eee3cc6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / flask_securitytxt-1.3.11-py3-none-any.whl

Download URL flask_securitytxt-1.3.11-py3-none-any.whl
Size 19.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
712a0baaba6cdbca6073c271a0b4a100b77ed57497643636cc3e97a29de09a6c
BLAKE2b-256 checksum
How to use checksums
1f4e1fa09d0707d1a6336a34620eecf04d7d0c41b97717fa0d25ed0654ceb893
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

1.4.0

2 release files

This release

1.3.11 This release

2 release files

1.3.10

2 release files

1.3.9

2 release files

1.3.8

2 release files

1.3.7

2 release files

1.3.6

2 release files

1.3.5

2 release files

1.3.4

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page