Search by

jeffersongoncalves / filament-security-headers

jeffersongoncalves

Filament settings page for laravel-security-headers: edit the Content Security Policy, response headers and HSTS from the panel, with a report-only mode to try a policy before enforcing it.

Package info

github.com/jeffersongoncalves/filament-security-headers

pkg:composer/jeffersongoncalves/filament-security-headers

Statistics

Installs: 420

Dependents: 29

Suggesters: 0

Stars: 1

Open Issues: 0

3.0.0 2026-10-09 02:42 UTC

README

Filament Security Headers

Filament Security Headers

Buy Me A Coffee

Latest Version on Packagist GitHub Code Style Action Status Total Downloads License

A Filament settings page for jeffersongoncalves/laravel-security-headers: edit the Content Security Policy, the response headers and HSTS from the panel instead of a config change and a deploy.

  • CSP directives as key/value pairs, the {nonce} placeholder included, plus the report URI
  • Report-only mode to try a new policy (Content-Security-Policy-Report-Only) before enforcing it
  • Response headers (X-Frame-Options, Referrer-Policy, Permissions-Policy...): edit, add, or leave a value empty to drop one
  • HSTS: on/off, max-age, subdomains, preload
  • Reset to config at any time

Until the page is saved, nothing changes: the middleware keeps using config/security-headers.php, and the page opens with those values. Header and directive names are validated and line breaks are rejected (no response splitting).

Compatibility

Branch Filament Package version
1.x 3.x ^1.0
2.x 4.x ^2.0
3.x 5.x ^3.0

Installation

composer require jeffersongoncalves/filament-security-headers:"^3.0"
php artisan vendor:publish --tag=filament-security-headers-settings-migrations
php artisan migrate

Set up laravel-security-headers first (the SecurityHeaders middleware on your routes).

Usage

use JeffersonGoncalves\Filament\SecurityHeaders\SecurityHeadersPlugin;

public function panel(Panel $panel): Panel
{
    return $panel
        ->plugins([
            SecurityHeadersPlugin::make()
                // optional: one of your panel's own groups (string or closure)
                ->navigationGroup(fn (): string => __('admin.navigation.settings')),
        ]);
}

The saved values are read once per request (one settings query; enable the spatie/laravel-settings cache to skip it). The header is built on every request — including pages served by a full-page cache such as laravel-page-cache — so a saved change applies right away; flushing the page cache does not change it.

Tightening the policy safely

  1. Turn on report-only, change the directive (e.g. swap 'unsafe-inline' for 'nonce-{nonce}' in script-src) and save.
  2. Browse the site and watch the browser console: report-only logs every violation without blocking anything.
  3. Fix what violates (inline scripts without the nonce, Alpine expressions that need 'unsafe-eval' — see Nonces and Alpine.js / Livewire without 'unsafe-eval'), then turn report-only off.

If something breaks after enforcing, put the old value back (or Reset to config) — no deploy needed. Proxies may also add scripts of their own (e.g. Cloudflare's Google tag gateway injects inline GTM without the nonce); check the page as a real browser receives it.

Requirements

Changelog

Please see CHANGELOG for more information on what has changed recently.

Contributing

Please see CONTRIBUTING for details.

Security Vulnerabilities

Please review our security policy on how to report security vulnerabilities.

Credits

License

The MIT License (MIT). Please see License File for more information.