Skip to content

Security and reporting

Security and reporting

This page covers the security-facing endpoints and request-layer protections that are exposed in source.

CSP violation reports

api/views/csp_report_view.py provides POST /api/v1/csp-report/.

Behavior:

  • accepts browser CSP report content types
  • parses JSON payloads
  • logs structured violation metadata
  • returns 204 No Content on success
  • returns 415 or 400 for bad content type / malformed body

The route is CSRF-exempt because browsers send the report cross-context.

Runtime protections

The middleware chain in backend_project/settings/core.py provides other security-related protections:

  • SecurityMiddleware
  • CSPMiddleware
  • CSRF middleware
  • authentication middleware
  • clickjacking protection
  • throttling on login endpoints when enabled

Why this page is separate

Security concerns here are operational and defensive rather than business logic. They deserve a dedicated page because the implementation spans endpoint behavior, middleware configuration, and logging semantics.

Validation

  • tests/unit/api/test_csp.py
  • security-related integration tests when present

Scope boundary

This page does not document auth flow details or tenancy rules. For those, read Authentication and consent and Tenancy.