DEBUG=False). No
configuration needed — they are applied by default and skipped in development.
Default CSP
Extending it
Custom directives are merged with the defaults, so you only specify what you are changing. For Stripe:config.py
Disabling
The strict
script-src 'self' is why inline <script> blocks and onclick= handlers
are feather check errors. Code that works in development would be
silently blocked by CSP in production.