Security Headers: security headers and CSP for PrestaShop 8 and 9
Install and configure Security Headers: test mode, CSP and violations, nonce and A+ grade, HSTS, Permissions-Policy, scanner, alerts and history.
DataFirefly Security Headers sends HTTP security headers from PrestaShop 8 and 9: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy. The module is set up in Advanced Parameters > Security headers, organised in six tabs: Dashboard, General and test mode, Content-Security-Policy, HSTS and other headers, Permissions-Policy and CSP violations.
Installation
- In Modules > Module Manager, click Upload a module and send the ZIP file.
- The module installs in test mode, with the CSP in Report-Only and violation collection on: no visitor is blocked.
- Open Advanced Parameters > Security headers. The Configure link of the Module Manager leads to the same place.
Going live step by step
The Going live checklist on the dashboard follows these steps and shows their state.
- Declare your test devices. General and test mode tab: click Add my IP address, or copy the test link and open it on your phone.
- Tick the services you use in the Content-Security-Policy tab, Third-party services block.
- Browse the shop from a test device: home, category, product page, cart, checkout up to payment, customer account. Violations appear in the CSP violations tab within a few minutes.
- Handle the violations: allow legitimate sources, ignore the others.
- Switch the CSP to Enforce once no new violation appears for 24 hours.
- Click Preview production on the dashboard to see the grade without test mode, then disable test mode.
- Check on a public scanner such as securityheaders.com or Mozilla Observatory, after purging your CDN cache if you use one.
Test mode
While test mode is active, each request gets one of these treatments:
- Test devices (IP in the list or browser opened with the test link): every header, CSP enforced whatever the chosen mode, HSTS capped at 5 minutes and without preload.
- Other visitors: only the CSP in Report-Only, if violation collection is on. Nothing is blocked, but their browsers report what would be.
Once test mode is disabled, every visitor receives the full configuration.
The IP list accepts IPv4 and IPv6 addresses and CIDR ranges, one per line. The test link marks the browser that opens it as a test device for 24 hours, useful for a phone on 4G whose IP changes. Open the same address with ?dfsh_test=off to stop earlier. Create a new link invalidates the previous links.
The Apply to the back office option sends HSTS, X-Frame-Options set to SAMEORIGIN, X-Content-Type-Options and Referrer-Policy in the back office. The CSP and Permissions-Policy are never applied there.
Content-Security-Policy
Directives
Each directive accepts sources separated by spaces or line breaks: keywords ('self', 'none', 'unsafe-inline', 'unsafe-eval'), hosts (https://www.example.com, *.example.com), schemes (data:, https:), nonces and hashes. Missing quotes around keywords are added. An invalid value is dropped and reported on save. An empty fetch directive falls back to default-src; other empty directives are not sent.
Third-party services
Each ticked service adds its domains to the directives it needs, without changing your own entries: Google Analytics 4 and Tag Manager, Google Ads, Google Fonts, reCAPTCHA, Google Maps, YouTube, Vimeo, Meta Pixel, TikTok, Pinterest, Stripe, PayPal, Mollie, Cookiebot, Axeptio, Hotjar, Microsoft Clarity, Trustpilot and Crisp. Providers change their domains from time to time: check the violations tab after enabling a service.
Options
- Include media servers: adds the servers set in Advanced Parameters > Performance to the image, script, style, font and media directives.
- Upgrade insecure requests: sends
upgrade-insecure-requestsin Enforce mode, on a shop using https. - URLs excluded from the CSP: one URL fragment per line. The CSP is not sent when the requested address contains one of them, for example a stubborn payment return page.
Nonce and the A+ grade
The default configuration keeps 'unsafe-inline' in script-src, because PrestaShop themes use inline scripts. Scanners then cap the grade at A. To aim for A+:
- In the Strict CSP with nonce block, enable Add a nonce to scripts while test mode is active.
- The module generates a random nonce on every page, adds it to every
<script>tag and removes'unsafe-inline'fromscript-src. - Browse the shop and handle the violations. Scripts inserted later by JavaScript without the nonce appear in the log, for example custom HTML tags in Google Tag Manager, which must use the GTM nonce variable.
- Once the log shows no
evalviolation, remove'unsafe-eval'fromscript-src.
The Keep inline event handlers option adds script-src-attr 'unsafe-inline' so that onclick attributes keep working. Leave it on unless your theme and modules use none; some public scanners flag it.
For developers: the page nonce is available in Smarty as {$dfsh_nonce} and in PHP with DfSecurityHeaders::getNonce(). It is added to the script tags of the HTML output automatically; these accessors are for code produced outside that output.
Violation log
Browser reports are grouped by directive and blocked source, with the number of hits, the date last seen, an example page and, for inline code, its first characters. Browser extensions are ignored. URLs are stored without parameters and no IP address is kept.
- Allow adds the source to the directive involved. If the directive was empty, it first takes the sources of
default-src. - Ignore removes the line without changing the CSP.
- The checkboxes let you Allow selected or Ignore selected. The directive buttons and the search field filter the list.
Allowing an inline or eval violation adds 'unsafe-inline' or 'unsafe-eval', which weakens the policy: moving the script to a file is better. With the nonce active, inline scripts without the nonce cannot be allowed automatically. Violations not seen for 30 days are deleted automatically.
HSTS and other headers
- HSTS: duration from 5 minutes to 2 years, 1 year by default. Browsers remember the header for the whole duration and refuse http.
includeSubDomainsforces https on every subdomain: only enable it if all of them support it.preloadis only sent withincludeSubDomainsand at least 1 year; only submit the domain to hstspreload.org if you are sure, removal takes months. - X-Frame-Options: SAMEORIGIN is recommended; DENY also blocks iframes of your own shop.
- X-Content-Type-Options: sends
nosniff. - Referrer-Policy:
strict-origin-when-cross-originby default. - Cross-Origin-Opener-Policy: off by default;
same-origin-allow-popupskeeps PayPal payment windows working. - Remove the X-Powered-By header hides the PHP version exposed by some servers.
Permissions-Policy
For each of the 19 features: Blocked disables it everywhere, This site only allows it on your domain and on the additional origins you enter, All sites opens it, Not set keeps the browser behaviour. Features a shop does not need (camera, microphone, geolocation, sensors, USB…) are blocked by default, and payment is limited to the site. The Stripe service adds its own origin to payment.
Scanner and grade
Analyze current headers requests a shop page from the server and shows the grade, the details per header, information leaks and the raw headers. Only the shop domains can be analyzed. Preview production simulates the configuration without test mode. The grade follows the same weighting as public scanners and remains indicative. The last analysis and the grade history stay visible after a reload.
Blocking alerts
In the General and test mode tab, enable Email alerts and enter up to 5 recipients. When the CSP is enforced and test mode is off, each resource that is really blocked and had never been seen triggers an email with the directive, the source and the page. New items are grouped, at most one email per hour. Send a test email checks the setup; if nothing arrives, check Advanced Parameters > E-mail.
History, export and import
Every change keeps the previous settings, with the date, the employee and the differences with the current state. The last 15 versions are kept; Restore goes back to one of them, and the replaced state joins the history.
Download the settings produces a JSON file without the secret tokens, to import on another shop, for example from staging to production. An import always enables test mode. Test IP addresses are imported too: check them.
Cache, CDN and server headers
- A CDN or page cache can serve old headers: purge it after each change.
- If your host or Cloudflare already adds some headers, the scanner flags the duplicates. Remove them on the server side or disable the header in the module.
- To let the server handle the headers, copy the Apache or Nginx block from the dashboard, then disable the module. Violation reporting and the nonce, which depend on the module, are not included.
Troubleshooting
- A page no longer works: restore the previous version in the history, or switch the CSP back to Report-Only while you fix it.
- Turn everything off: disable Send security headers in the General tab, or disable the module.
- HSTS: a browser that received HSTS refuses http until the duration expires, even after the module is disabled. This is why test devices only get 5 minutes.