Repository navigation
fix(security): default CSP_ENFORCE to enforced in production/staging (#1107) - #1154
Merged
nanaf6203-bit merged 1 commit intoSep 30, 2026
Merged
Conversation
…ettaChain#1107) CSP_ENFORCE previously defaulted to false, so production served no nonce-based CSP unless operators explicitly opted in — an insecure default that made the production posture ambiguous. Secure, environment-aware default: - unset/empty: enforced in production/staging, disabled in development - "true"/"false": explicit override (false warns at boot outside dev) Also: - Schema rejects values other than "true"/"false"/"" (MettaChain#1107) - .env.example documents the default and how to verify - docs/csp.md: decision table, curl -I verification steps, exclusions check - validate-env.cjs warns when CSP is explicitly disabled in production - Unit tests pin the default behavior in middleware and schema Generated with Codebuff 🤖 Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@Penielka Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves #1107
CSP_ENFORCEpreviously defaulted tofalse, so the nonce-based CSP insrc/middleware.tswas never applied in production unless operators explicitly opted in. Production posture was ambiguous: teams could believe nonce CSP was active while enforcement was off.Decision (per the issue's recommendation)
Enforce in production/staging, warn in dev — implemented as a secure, environment-aware default:
CSP_ENFORCE"true""false"No configuration is required for a secure production deployment; an explicit opt-out is now loudly visible instead of silently default.
Changes
src/middleware.ts—resolveCspEnforcement()applies the environment-aware default; warns when explicitly disabled outside development.src/config/env/schema.ts—CSP_ENFORCEnow validates as"true"/"false"/""(invalid values fail env validation), defaulting to enforced in production/staging. Mirrors the middleware logic..env.example— documents the secure default and verification.docs/csp.md— decision table,curl -Iverification steps (header presence, per-request nonce uniqueness, exclusion checks), and troubleshooting guidance.scripts/validate-env.cjs— warns when CSP is explicitly disabled in production.Acceptance criteria (from the issue)
.env.example,docs/csp.md)CSP_ENFORCEbooleancurl -Iindocs/csp.md)Testing
npx jest src/config/env/__tests__/schema.test.ts src/config/env/__tests__/validator-parity.test.ts— 30/30 pass-t "1107")upstream/mainwithout these changes (environment-related, out of scope)eslintclean on all touched files; no newtscerrors introduced (repo has pre-existing unrelated ones)Verification snippet (also in docs/csp.md)