Filament Security Headers
#Filament Security Headers
A Filament settings page for jeffersongoncalves/laravel-security-headers: edit the Content Security Policy, the response headers and HSTS from the panel instead of a config change and a deploy.
- CSP directives as key/value pairs, the
{nonce}placeholder included, plus the report URI - Report-only mode to try a new policy (
Content-Security-Policy-Report-Only) before enforcing it - Response headers (
X-Frame-Options,Referrer-Policy,Permissions-Policy...): edit, add, or leave a value empty to drop one - HSTS: on/off, max-age, subdomains, preload
- Reset to config at any time
Until the page is saved, nothing changes: the middleware keeps using config/security-headers.php, and the page opens with those values. Header and directive names are validated and line breaks are rejected (no response splitting).
#Compatibility
| Branch | Filament | Package version |
|---|---|---|
| 1.x | 3.x | ^1.0 |
| 2.x | 4.x | ^2.0 |
| 3.x | 5.x | ^3.0 |
#Installation
composer require jeffersongoncalves/filament-security-headers:"^3.0" php artisan vendor:publish --tag=filament-security-headers-settings-migrations php artisan migrate
Set up laravel-security-headers first (the SecurityHeaders middleware on your routes).
#Usage
use JeffersonGoncalves\Filament\SecurityHeaders\SecurityHeadersPlugin; public function panel(Panel $panel): Panel { return $panel ->plugins([ SecurityHeadersPlugin::make() // optional: one of your panel's own groups (string or closure) ->navigationGroup(fn (): string => __('admin.navigation.settings')), ]); }
The saved values are read once per request (one settings query; enable the spatie/laravel-settings cache to skip it).
#Requirements
- PHP 8.2 or higher
- Filament 5.x
- jeffersongoncalves/laravel-security-headers 2.x
#Changelog
Please see CHANGELOG for more information on what has changed recently.
#Contributing
Please see CONTRIBUTING for details.
#Security Vulnerabilities
Please review our security policy on how to report security vulnerabilities.
#Credits
#License
The MIT License (MIT). Please see License File for more information.