Security and reporting
Security and reporting
This page covers the security-facing endpoints and request-layer protections that are exposed in source.
CSP violation reports
api/views/csp_report_view.py provides POST /api/v1/csp-report/.
Behavior:
- accepts browser CSP report content types
- parses JSON payloads
- logs structured violation metadata
- returns
204 No Contenton success - returns
415or400for bad content type / malformed body
The route is CSRF-exempt because browsers send the report cross-context.
Runtime protections
The middleware chain in backend_project/settings/core.py provides other security-related protections:
SecurityMiddlewareCSPMiddleware- CSRF middleware
- authentication middleware
- clickjacking protection
- throttling on login endpoints when enabled
Why this page is separate
Security concerns here are operational and defensive rather than business logic. They deserve a dedicated page because the implementation spans endpoint behavior, middleware configuration, and logging semantics.
Validation
tests/unit/api/test_csp.py- security-related integration tests when present
Scope boundary
This page does not document auth flow details or tenancy rules. For those, read Authentication and consent and Tenancy.