Skip to main content

Description

csp-scan is a Python script for constructing strict content-security-policy headers based on content of HTML files in a source directory. It looks for used sources and hrefs in HTML elements for most CSP directives and outputs the header content.

Includes a warning system for unencrypted HTTP connections.

Installation

pip3 install csp-scan

Usage

cd my-frontend-src

csp-scan

Options

-d, --default-src

Value for default src directive. Default: self

-r, --report-uri

Report URI to post violations to.

-l, --literal-src

Include whole src paths in the CSP.

Contribution / forking

Contributions welcome!

Context

Directive class is initiated with a name of the directive (e.g. script-src, style-src...). Uses regex to locate specific attribute in a HTML element, given an optional pre-condition or file format.

File definitions.py creates directive objects and defines their conditions through add_search_instruction method. If you want to add a directive or modify a search condition, do it there.

style_src.add_search_instruction(
    tag = "link",
    attribute = "href",
    format = ".css"
)

This instruction will find and classify this source as style-src:

<link href="https://maxcdn.bootstrapcdn.com/font-awesome/4.6.0/css/font-awesome.min.css"/>

But not this:

<link href="https://somecdn/js/somejsfile.js"/>
style_src.add_search_instruction(
    tag = "link",
    attribute = "href",
    condition = ("rel", "stylesheet")
)

This instruction will find and classify this source as style-src:

<link
    href="https://fonts.googleapis.com/css2?family=Montserrat:wght@100;400;500;600;700&display=swap"
    rel="stylesheet"
/>

But not this:

<link href="https://maxcdn.bootstrapcdn.com/font-awesome/4.6.0/css/font-awesome.min.css"/>
style_src.add_search_instruction(
    tag = "link",
    attribute = "href"
)

This instruction would find and classify all of the above examples.

Metadata

Release files for csp-scan 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for csp-scan 1.0.0
File Size Uploaded
csp-scan-1.0.0.tar.gz 5.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for csp-scan 1.0.0
File Interpreter ABI Platform
csp_scan-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.3 kB

Release files / csp-scan-1.0.0.tar.gz

Download URL csp-scan-1.0.0.tar.gz
Size 5.2 kB
Tags Source
SHA-256 checksum
How to use checksums
36a9bcfb8fce095ecbc2107099b85ba0902d10eabaf56274c97a6bf4a0088951
BLAKE2b-256 checksum
How to use checksums
e8fa89b05ce3193173bc05cd1d225edd2c13d9d7af0dd6baf21d54b1e8105af8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.10.2

Release files / csp_scan-1.0.0-py3-none-any.whl

Download URL csp_scan-1.0.0-py3-none-any.whl
Size 6.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5cea722fd526e4e7ef9ab574ba41382ba37b997d45264bbb1c74c2cc627689f6
BLAKE2b-256 checksum
How to use checksums
ee3e933c0b8c2073a24cc3b5e71bc88f25dadb5e058b84f155e383e6747b5d60
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.0 CPython/3.10.2

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page