Skip to main content

secure-aiohttp

Library implements CSP and HSTS headers. In future CSRF token and maybe some other default security handlers will be added.

HSTS(Strict-Transport-Security)

Way for web site to tell browsers that it should only be accessed using HTTPS, instead of using HTTP. Which is usually used for connection, even if web site enables HTTPS. Helps to avoid man in the middle attack.(source) You can learn more here:

Avaliable parameters:

Parameter Defenition Default
hsts should HSTS header be added True
hsts_max_age for how long in seconds browser should redirect directly to HTTPS 31536000(one year)
hsts_inclue_subdomains should include subdomains True
hsts_preload should use preload True

CSP(Content-Security-Policy)

Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement to distribution of malware.(source) Basically it block all sources for front-end libraries/images/objects... that are not specified in whitelist to avoid downloading malicious code that can gather sensetive user data. You can learn more here:

Avaliable parameters:

Parameter Defenition Default
csp Should CSP header be added and if yes - what it should include None
csp_testing Enable CSP in report only mode, without actually blocking sources False
scp_report_uri Where browser should send CSP reports /secureaiohttp-csp-report-uri

csp parameter can be either:

  • None to avoid using CSP header at all
  • default|same-origin|google-analitycs to use predifined CSP header
  • dict with custom CSP parameters, example:

'myCSP': {
    'connect-src': 'self',
    'default-src': 'none',
    'img-src': 'self',
    'script-src': 'self',
    'style-src': 'self',
    'report-uri': '/my-csp-report-handler',
    'block-all-mixed-content': None
}


You need to pass None for parameters that require no values, like block-all-mixed-content.

Predifined CPS header variants are taken from https://content-security-policy.com/ and include:

  • default: This policy allows images, scripts, AJAX, and CSS from the same origin, and does not allow any other resources to load (eg object, frame, media, etc). It is a good starting point for many sites.
  • google-analitycs: Allow Google Analytics, Google AJAX CDN and Same Origin.
  • same-origin: Only Allow Scripts from the same origin.

Examples

You can see some simple examples in example folder.

Contribution

Any contributions are welcome! Take action in securing your users! ;)

License

secure-aiohttp is offered under the Apache 2 license.

Release files for secure-aiohttp 0.0.24

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secure-aiohttp 0.0.24
File Size Uploaded
secure-aiohttp-0.0.24.tar.gz 4.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secure-aiohttp 0.0.24
File Interpreter ABI Platform
secure_aiohttp-0.0.24-py3-none-any.whl Python 3 none any Details

Total release size: 14.3 kB

Release files / secure-aiohttp-0.0.24.tar.gz

Download URL secure-aiohttp-0.0.24.tar.gz
Size 4.6 kB
Tags Source
SHA-256 checksum
How to use checksums
d97360a2033a022a6594028f7463e45f4e4be8b42f801e564012269bbf1be2e6
BLAKE2b-256 checksum
How to use checksums
f5cc17c7ee84764e9b0713e8edec77c15f32fff371067f61e8adfd88f190c747
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.21.0 setuptools/46.0.0 requests-toolbelt/0.9.1 tqdm/4.43.0 CPython/3.7.7

Release files / secure_aiohttp-0.0.24-py3-none-any.whl

Download URL secure_aiohttp-0.0.24-py3-none-any.whl
Size 9.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ab09964cb5621e27861f2fa9762a34dbe02bc0f6c29e6118aad10c5b9bd5a617
BLAKE2b-256 checksum
How to use checksums
c2a8882bb5dea2d4422e52e674b745f39a34d8675630600f2ac5c9c571267378
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.21.0 setuptools/46.0.0 requests-toolbelt/0.9.1 tqdm/4.43.0 CPython/3.7.7

Release history Release notifications | RSS feed

This release

0.0.24 This release

2 release files

0.0.22

2 release files

0.0.21

2 release files

0.0.2

1 release file

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page