Why when I check the Response Headers of the first HTTP response I see no CSP?
No Content Security Policy is set in Streamlit pages?
(I’m using streamlit cloud to host my webpage)
Why when I check the Response Headers of the first HTTP response I see no CSP?
No Content Security Policy is set in Streamlit pages?
(I’m using streamlit cloud to host my webpage)
Hi @Fedruscia,
I know this thread is pretty old, but wanted to update you on this issue after touching base with our development team.
Unfortunately, Streamlit doesn’t currently support setting security headers. While we are considering enhancements in this area we are not expecting any major support to be implemented in the next six months. Given that meaningful improvements to the library in this area won’t be prioritized in the near term, we recommend seeking other solutions if this is an urgent need for your use case.
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.
These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us understand how visitors move around the site and which pages are most frequently visited.
These cookies are used to record your choices and settings, maintain your preferences over time and recognize you when you return to our website. These cookies help us to personalize our content for you and remember your preferences.
These cookies may be deployed to our site by our advertising partners to build a profile of your interest and provide you with content that is relevant to you, including showing you relevant ads on other websites.