Download the PHP package asignua/filament-csp-nonce without Composer

On this page you can find all versions of the php package asignua/filament-csp-nonce. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package filament-csp-nonce

Filament CSP Nonce

Stand With Ukraine Latest Version on Packagist Tests Total Downloads License Plumb score

Filament CSP Nonce

A per-request CSP nonce, a ready Content-Security-Policy header and a violation report endpoint for Filament panels, without overriding a single Filament view.

Without nonces, a Content-Security-Policy for Filament needs 'unsafe-inline' for scripts, which defeats the point (filamentphp/filament#7032, #8329). Filament and Livewire already print the nonce on their asset tags when Laravel's Vite::useCspNonce() is set, but a handful of Filament's own inline <script> and <style> tags have none. This package sets the nonce, closes those gaps and sends the header.

Read What this does and does not protect before relying on it. Filament needs 'unsafe-eval'. That is a property of Alpine, not of this package.

Screenshots

The Content-Security-Policy header the plugin sends for a panel page (default strict-dynamic preset, captured from the Testbench workbench; the nonce is different on every request). All 18 <script>/<style> tags of the list page carry it.

Response headers with the strict-dynamic policy

Requirements

Installation

No assets to publish (filament:assets is not needed: the package ships no CSS or JS).

Usage

Everything is optional:

Outside panels (your public pages), use the middleware alias and the helpers:

Presets

Preset script-src style-src
filament-strict-dynamic (default) 'nonce-…' 'strict-dynamic' 'unsafe-eval' 'self' 'nonce-…' + style-src-attr 'unsafe-inline'
filament-compatible 'self' 'nonce-…' 'unsafe-eval' (same-origin scripts keep working, e.g. third-party plugin assets) 'self' 'unsafe-inline'

Both add default-src 'self', object-src 'none', base-uri 'self', form-action 'self', frame-ancestors 'self', img-src 'self' data: blob: https:, font-src 'self' data:, connect-src 'self', media-src 'self' blob: data:, worker-src 'self' blob:, report-uri and report-to.

->directives() and ->allowInlineStyles() accumulate in any order; a later value for the same directive wins. A CspPolicy instance passed to ->policy() is cloned per request, so it can be shared between panels.

Violation reports

POST /csp/report (no session, no CSRF, throttled) accepts both report-uri and Reporting API bodies, strips query strings, caps the payload at 16 KB and stores per report.storage: log (default), database (publish the migration; identical violations fold into one row with a hit counter; prune with php artisan csp:prune) or null.

The endpoint is public and unauthenticated, so every report field is attacker-controlled. The limits below protect storage (the table, the log, the cache), not report completeness: a flood of forged reports can use up the per-minute budget or fill the row cap and crowd out genuine violations, so treat a report-only rollout as a hint, not as proof that nothing breaks.

There is no UI for stored violations: query the table (or build a Filament resource on Asignua\FilamentCspNonce\Models\CspViolation).

What this does and does not protect

What you get with the default preset (measured in a real browser against Filament 5.9, see FEASIBILITY.md):

What you do not get:

Configuration

config/csp-nonce.php: enabled (env CSP_ENABLED), report_only (CSP_REPORT_ONLY), preset, directives, report.* (enabled, path, throttle, storage, log_channel, table, retention_days, allowed_hosts, max_new_per_minute, max_rows, prune_schedule) and blade.* (rewrite, packages fnmatch patterns of Composer packages whose templates get nonces, paths).

Third-party Filament plugins that print bare <script>/<style> tags: add their package to blade.packages (['filament/*', 'awcodes/*']) and run php artisan view:clear.

Gotchas

Uninstalling

Compiled views reference \Asignua\FilamentCspNonce\Nonce. Run php artisan view:clear right after removing the package, or every panel page fails with "class not found".

Translations

The package has no UI strings, so no language files.

AI agents

Laravel Boost guidelines ship in resources/boost/guidelines/core.blade.php.

Testing

browser/audit.mjs is a manual, real-browser audit (puppeteer-core + Edge/Chrome) against the workbench; it is how the claims above were measured.

Changelog

See CHANGELOG.

License

MIT. See LICENSE.


All versions of filament-csp-nonce with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
filament/filament Version ^5.0
illuminate/contracts Version ^12.0|^13.0
spatie/laravel-package-tools Version ^1.16
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package asignua/filament-csp-nonce contains the following files

Loading the files please wait ...