In ServerHttpSecurity.HeaderSpec.ContentSecurityPolicySpec, reportOnly(boolean) and policyDirectives(String) return HeaderSpec instead of ContentSecurityPolicySpec. That prevents method chaining inside the lambda, unlike the servlet ContentSecurityPolicyConfig (and unlike the newer nonceAttributeName(...), exchangeMatcher(...) and exchangeMatchers(...) methods from #18499, which return ContentSecurityPolicySpec).
Changing a return type is not binary compatible, so this likely needs new methods plus deprecation of the existing ones. @ziqin explored this in #18499 (reportOnly() and directives(String) on ContentSecurityPolicySpec) and noted the naming inconsistency with the servlet and Kotlin DSLs; it was deferred so that #18499 could stay focused on nonce support.
Happy to review a pull request for this.
In
ServerHttpSecurity.HeaderSpec.ContentSecurityPolicySpec,reportOnly(boolean)andpolicyDirectives(String)returnHeaderSpecinstead ofContentSecurityPolicySpec. That prevents method chaining inside the lambda, unlike the servletContentSecurityPolicyConfig(and unlike the newernonceAttributeName(...),exchangeMatcher(...)andexchangeMatchers(...)methods from #18499, which returnContentSecurityPolicySpec).Changing a return type is not binary compatible, so this likely needs new methods plus deprecation of the existing ones. @ziqin explored this in #18499 (
reportOnly()anddirectives(String)onContentSecurityPolicySpec) and noted the naming inconsistency with the servlet and Kotlin DSLs; it was deferred so that #18499 could stay focused on nonce support.Happy to review a pull request for this.