Skip to content

basalt / http/src / pageCsp

Function: pageCsp() ​

> pageCsp(options?): string

Defined in: http/src/html.ts:64

A locked-down, route-scoped CSP for a self-contained HTML page: everything denied by default; inline scripts allowed ONLY by hash; styles inline (style-src 'unsafe-inline' — hash sources cannot cover style="" attributes); fetch restricted to 'self' plus the given origins. Set it on the route's response so it overrides the app-wide default from securityPlugin for that page only.

Parameters ​

options? ​

PageCspOptions = {}

Returns ​

string

Released under the MIT License.