From e609c39b993968d8dcb2e7a6b083c11063b5b05f Mon Sep 17 00:00:00 2001 From: Jacob Coffee Date: Thu, 8 Oct 2026 00:00:39 -0500 Subject: [PATCH] Omit CSP report-uri when CSP_REPORT_URI is unset django-csp skips directives whose value is None, but wrapping the setting in a list sent the literal 'report-uri None' locally, so browsers POSTed violation reports to /None. --- pydotorg/settings/base.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pydotorg/settings/base.py b/pydotorg/settings/base.py index 611579caf..a9403580f 100644 --- a/pydotorg/settings/base.py +++ b/pydotorg/settings/base.py @@ -350,7 +350,7 @@ "base-uri": [SELF], "object-src": ["'none'"], "form-action": [SELF], - "report-uri": [_CSP_REPORT_URI], + "report-uri": _CSP_REPORT_URI, # When we upgrade to Django 6, begin using # 'report-to' and 'Reporting-Endpoints' header. # django-csp doesn't support automatically