All tools / Security & hardening
asgiwarden
One hardening kit for FastAPI and Starlette.
Buy asgiwarden for $99One payment of $99, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.
See it work
asgiwarden csp-hash asgiwarden/examples/page.html
# 1 inline script(s) hashed
Content-Security-Policy: default-src 'self'; script-src 'self' 'sha256-hlwtJvDW+zff6mAihgc8VJ6jlHcWB1+SBRlz8dR/wvA='; style-src 'self'; font-src 'self'; img-src 'self' data:; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'
What it does
Security headers, the real visitor IP behind Cloudflare, a rate limit, request ids, log redaction and throttled error alerts, installed in the right order with one harden(app) call.
- Security headers
- Frame policy, nosniff, HSTS, and a CSP built from sha256 hashes of your inline scripts. HEAD is answered like GET.
- Real client IP
- Trusts Cloudflare headers only when the request came from a Cloudflare edge. A forged X-Forwarded-For cannot mint new rate-limit buckets when trusted_hops matches your proxies (0 if none). Bundled ranges plus a refresh-cloudflare command.
- Rate limit
- A sliding window by IP and by session.
- Request ids and alerts
- A request id on every log line, secrets and PII redacted, and one alert per bug through an on_alert callback.
- A CSP you can check
- asgiwarden csp-hash prints the policy for a page and exits non-zero when it has an inline handler that no hash can allow, so it can run in CI.
What you get
asgiwarden 1.0.2: the Python package and the asgiwarden command, with an example app, a before-and-after script and the full test suite, with 255 automated tests.
A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.
Every update. New versions land in the same repository; git pull to get them.
Requirements
Python 3.10 or newer. Python 3.10 or newer and Starlette, which installs with it. FastAPI is optional.
How buying works
- Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
- Pay $99, plus any sales tax shown at checkout, on Stripe's checkout page.
- Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at
github.com/dominares-tools/asgiwarden/invitations. Invitations expire after 7 days; you can get a new one any time. - Clone and install:
git clone https://github.com/dominares-tools/asgiwarden.gitPrivate repo: sign in to GitHub on this computer first. Run
gh auth loginand choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clonegit@github.com:dominares-tools/asgiwarden.git.python3 -m venv .venv && . .venv/bin/activate pip install ./asgiwarden
Questions
Do I need GitHub?
Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.
Can I get a refund?
Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.
Who takes the payment?
Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.
Something wrong?
Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.