Skip to main content

Set the draft security HTTP header Feature-Policy on your Django app.

Project description


Set the draft security HTTP header Feature-Policy on your Django app.


Tested with all combinations of:

  • Python: 3.6
  • Django: 2.0, 2.1


Install with pip:

pip install django-feature-policy

Then add the middleware, best after Django’s SecurityMiddleware as it does similar addition of security headers that you’ll want on every response:


By default no header will be set, configure the setting as below.


Change the FEATURE_POLICY setting to configure what Feature-Policy header gets set.

This should be a dictionary laid out with:

  • Keys as the names of browser features - a full list is available on the MDN article.
  • Values as lists of strings, where each string is either an origin, e.g. '', or of the special values 'self', 'none', or '*'. If there is just one value, no containing list is necessary. Note that in the header, special values like 'none' include single quotes around them - do not include these quotes in your Python string, they will be added by the middleware.

If the keys or values are invalid, ImproperlyConfigured will be raised at instantiation time, or when processing a response. The current feature list is pulled from the JavaScript API with document.policy.allowedFeatures() on the latest Chrome build.


Disable geolocation from running in the current page and any iframe:

    'geolocation': 'none',

Allow autoplay from the current origin and iframes from

    'autoplay': ['self', ''],


Pending release

1.0.0 (2018-10-24)

  • First release, supporting adding the header with a middleware.

Project details

Release history Release notifications

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Filename, size & hash SHA256 hash help File type Python version Upload date
django_feature_policy-1.0.0-py2.py3-none-any.whl (4.0 kB) Copy SHA256 hash SHA256 Wheel 3.7
django-feature-policy-1.0.0.tar.gz (5.0 kB) Copy SHA256 hash SHA256 Source None

Supported by

Elastic Elastic Search Pingdom Pingdom Monitoring Google Google BigQuery Sentry Sentry Error logging AWS AWS Cloud computing DataDog DataDog Monitoring Fastly Fastly CDN SignalFx SignalFx Supporter DigiCert DigiCert EV certificate StatusPage StatusPage Status page