Skip to content

Releases: paragonie/csp-builder

Version 2.2.0

09 Nov 00:11
v2.2.0
146fd5e
Compare
Choose a tag to compare
  • Add dedicated API method for setting report-to/report-uri directives.
  • Add support for 'strict-dynamic' and 'unsafe-hashed-attributes'

Version 1.4.0

09 Nov 00:08
v1.4.0
Compare
Choose a tag to compare

Contains a year of bugfixes and tweaks from the v2 branch, backported for PHP 5 support.

Version 2.1.0

24 Jul 20:08
v2.1.0
Compare
Choose a tag to compare
  • Added several helper methods, e.g. setDataAllowed() and setSelfAllowed(), for programatically allowing self and data: URIs for a specific directive.
  • CSP-Builder is now type-safe! This can be verified by Psalm. In future releases, this will be enforced by Travis CI.
  • Docblock and unit test cleanup.

Version 2.0.1

01 Nov 17:57
v2.0.1
Compare
Choose a tag to compare

Allow CSPBuilder instances to be instantiated from a JSON string. Thanks @renanmpimentel

Version 1.3.3

01 Nov 17:55
v1.3.3
Compare
Choose a tag to compare

Version 1.3.2 broke somewhere in the git chain, so v1.3.3 it is.

Version 2.0.0

09 Apr 23:20
Compare
Choose a tag to compare

Version 2.0.0 requires PHP 7.

This allows us to use strict typing and drop random_compat as a dependency.

Version 1.3.1

22 Feb 23:44
Compare
Choose a tag to compare
  • Minor (some annoying) bug fixes
  • Fix whitespace in unsafe-eval directives

Full list here: v1.3.0...v1.3.1

Version 1.3.0

01 Feb 05:48
Compare
Choose a tag to compare

A lot of bugfixes since 1.2.0.

BC break: Changed our erroneous connect-uri and font-uri directives to connect-src and font-src respectively.

Before version 1.4, I'd like to improve the documentation and unit test coverage. Feel free to open any issues for bugs you encounter or feature requests you might have.

Version 1.2.4

30 Jan 20:20
Compare
Choose a tag to compare

Use normal Base64 encoding for CSP hashes.

Version 1.2.3

29 Jan 21:33
Compare
Choose a tag to compare

It turns out that the hash directive just needs to be sha256-blah not hash-sha256-blah.