Skip to content

fix(security): default CSP_ENFORCE to enforced in production/staging (#1107) - #1154

Merged
nanaf6203-bit merged 1 commit into
MettaChain:mainfrom
Penielka:fix/csp-enforce-secure-default
Sep 30, 2026
Merged

nanaf6203-bit merged 1 commit into
MettaChain:mainfrom
Penielka:fix/csp-enforce-secure-default

Conversation

@Penielka

@Penielka Penielka commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Resolves #1107

CSP_ENFORCE previously defaulted to false, so the nonce-based CSP in src/middleware.ts was never applied in production unless operators explicitly opted in. Production posture was ambiguous: teams could believe nonce CSP was active while enforcement was off.

Decision (per the issue's recommendation)

Enforce in production/staging, warn in dev — implemented as a secure, environment-aware default:

CSP_ENFORCE Environment Behaviour
"true" Any CSP enforced
"false" Any CSP disabled (logs a boot warning outside development)
unset / empty production, staging CSP enforced — secure default
unset / empty development CSP off (dev convenience: hot reload, no nonce bookkeeping)

No configuration is required for a secure production deployment; an explicit opt-out is now loudly visible instead of silently default.

Changes

  • src/middleware.ts — resolveCspEnforcement() applies the environment-aware default; warns when explicitly disabled outside development.
  • src/config/env/schema.ts — CSP_ENFORCE now validates as "true" / "false" / "" (invalid values fail env validation), defaulting to enforced in production/staging. Mirrors the middleware logic.
  • .env.example — documents the secure default and verification.
  • docs/csp.md — decision table, curl -I verification steps (header presence, per-request nonce uniqueness, exclusion checks), and troubleshooting guidance.
  • scripts/validate-env.cjs — warns when CSP is explicitly disabled in production.
  • Tests — middleware: enforced-by-default in production / off in dev when unset; schema: environment-aware default, invalid-value rejection, explicit override.

Acceptance criteria (from the issue)

  • Default value decided and documented (.env.example, docs/csp.md)
  • Schema validates CSP_ENFORCE boolean
  • Docs include verification steps (curl -I in docs/csp.md)

Testing

  • npx jest src/config/env/__tests__/schema.test.ts src/config/env/__tests__/validator-parity.test.ts — 30/30 pass
  • New tests: 5/5 pass (-t "1107")
  • Pre-existing auth-matrix middleware test failures reproduce identically on upstream/main without these changes (environment-related, out of scope)
  • eslint clean on all touched files; no new tsc errors introduced (repo has pre-existing unrelated ones)

Verification snippet (also in docs/csp.md)

curl -sI https://your-domain.example.com/ | grep -i content-security-policy
# → content-security-policy: default-src 'self'; script-src 'self' 'nonce-...'; ...

…ettaChain#1107)

CSP_ENFORCE previously defaulted to false, so production served no
nonce-based CSP unless operators explicitly opted in — an insecure
default that made the production posture ambiguous.

Secure, environment-aware default:
- unset/empty: enforced in production/staging, disabled in development
- "true"/"false": explicit override (false warns at boot outside dev)

Also:
- Schema rejects values other than "true"/"false"/"" (MettaChain#1107)
- .env.example documents the default and how to verify
- docs/csp.md: decision table, curl -I verification steps, exclusions check
- validate-env.cjs warns when CSP is explicitly disabled in production
- Unit tests pin the default behavior in middleware and schema

Generated with Codebuff 🤖
Co-Authored-By: Codebuff <noreply@codebuff.com>
@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@Penielka Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@nanaf6203-bit nanaf6203-bit left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nanaf6203-bit
nanaf6203-bit merged commit eb7753e into MettaChain:main Sep 30, 2026
2 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CSP_ENFORCE defaults to false; decide and document production default

2 participants