Skip to main content

Flask-Helmet

PyPI version

Flask-Helmet is a Flask extension that makes it easy to add security headers to your HTTP responses. The goal of this project is to help you build more secure web applications by providing a simple and flexible API for adding headers that improve the security of your application.

Installation

You can install Flask-Helmet using pip:

pip install flask-helmet

Usage

To use Flask-Helmet in your Flask application, you need to do the following:

Import the extension:

from flask_helmet import FlaskHelmet

Initialize the extension:

helmet = FlaskHelmet()
helmet.init_app(app)

Headers

Flask-Helmet supports the following headers:
X-XSS-Protection: This header is used to configure the browser's XSS
X-Content-Type-Options: This header is used to prevent browsers from interpreting files as a different MIME type.
Content-Security-Policy: This header is used to control the resources that a browser is allowed to load for a given page.
X-Frame-Options: This header prevents browsers from displaying the content of the site in a frame.
Strict-Transport-Security: This header enforces secure (HTTPS) connections to the server.
Referrer-Policy: This header specifies the value of the Referer header sent with requests.
X-Permitted-Cross-Domain-Policies: This header controls the delivery of Adobe Flash content, including Flash cookies (LSOs).
X-Download-Options: This header tells Internet Explorer 8 and later to prevent file downloads from executing.
X-DNS-Prefetch-Control: This header controls browser DNS prefetching.
X-Powered-By: This header identifies the technology used to build the site.

For more information on the headers supported by Flask-Helmet, see the official documentation.

Contributing

If you want to contribute to Flask-Helmet, you can do so by submitting a pull request on Github. Before submitting your pull request, be sure to run the tests and make sure that your code follows the PEP 8 style guide.

  1. Fork the repository.
  2. Create a new branch for your changes.
  3. Make your changes and write tests for them.
  4. Submit a pull request.

License

Flask-Helmet is released under the MIT License. See the LICENSE file for more information.

We welcome contributions to this library. If you have an idea for a new feature or have found a bug, please open an issue on Github.

Buy me a Coffee

ko-fi

Release files for flask-helmet 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flask-helmet 1.0.0
File Size Uploaded
flask-helmet-1.0.0.tar.gz 3.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flask-helmet 1.0.0
File Interpreter ABI Platform
flask_helmet-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 8.3 kB

Release files / flask-helmet-1.0.0.tar.gz

Download URL flask-helmet-1.0.0.tar.gz
Size 3.8 kB
Tags Source
SHA-256 checksum
How to use checksums
e35c9de314b12f7ae87eb720937354f338e3b12a4f9a120598775c51f2fa2409
BLAKE2b-256 checksum
How to use checksums
9e442115ae076506b6dd96d1ef778f41349936d23e60cb5fef898b7031a31195
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.8.1

Release files / flask_helmet-1.0.0-py3-none-any.whl

Download URL flask_helmet-1.0.0-py3-none-any.whl
Size 4.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d55f7ceace736c024714dc1278bdafbaf04f7d3d9c2aaf541b33fb91335eb47a
BLAKE2b-256 checksum
How to use checksums
4a3dfabe57292d988496b5b835a91b3f11d89e563e1e7d630cdd8fba13ac0313
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.8.1

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page