$npx skillfedfor your agent

django-permissions-policy

Set the Permissions-Policy HTTP header on your Django app.

Worth itPyPI Dynamic ContentReleased Aug 2026466.3K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — django_permissions_policy-4.33.0-py3-none-any.whl
v4.33.0 · released 2026-08-14 · Python >=3.10 · 2 runtime deps: asgiref, django

Yes. The package is actively maintained, has no known vulnerabilities, integrates seamlessly into Django's middleware stack with low friction, and solves a real security/privacy concern with minimal configuration. Use it if you want to control browser feature access in your Django app.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Django 5.2 to 6.1 and Python 3.10 to 3.15.
  • Low install friction with a pure Python wheel.
  • Actively maintained with a recent release and straightforward middleware integration into Django's standard stack.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects.

last release 2026-08-14 (0 days) · last repo commit 2026-08-14 · 118 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 466,341 downloads/mo, #6,504 on PyPI

Verify before relying

# Install
python -m pip install django-permissions-policy

# In settings.py, add to MIDDLEWARE after SecurityMiddleware:
MIDDLEWARE = [
    "django.middleware.security.SecurityMiddleware",
    "django_permissions_policy.PermissionsPolicyMiddleware",
]

# Configure the policy:
PERMISSIONS_POLICY = {
    "geolocation": [],
    "camera": [],
    "microphone": [],
}

# In a view, optionally override:
from django_permissions_policy.decorators import permissions_policy_override

@permissions_policy_override({"camera": ["self"]})
def video_call_view(request):
    pass
  • Whether the package validates against the full current W3C feature list or relies on browser-reported features
  • Performance impact when processing responses with complex permission policies
Same gist for agents: .md · .json

What it is and what it does

django-permissions-policy is a Django middleware that injects the Permissions-Policy HTTP header into your application's responses, allowing you to declaratively restrict which browser capabilities (geolocation, camera, microphone, payment APIs, etc.) are available to scripts running on your pages. You configure it via a Django setting that maps feature names to lists of allowed origins, then the middleware automatically adds the header to every response. It also supports a report-only mode for testing policies before enforcement, and per-view decorator overrides for fine-grained control.

The package depends only on Django and asgiref, integrating cleanly into Django's middleware pipeline. It validates configuration at instantiation time to catch policy errors early, and supports both the enforced Permissions-Policy header and the non-enforcing Permissions-Policy-Report-Only header for gradual rollout. The middleware can be instantiated with explicit policy dictionaries for advanced use cases like dispatching between multiple policies within another middleware.

Use it for

  • Disable privacy-invasive features like geolocation and camera across your entire Django app by default.
  • Allow autoplay only from your own origin and trusted third-party iframe sources.
  • Test a restrictive permissions policy in report-only mode before enforcing it site-wide.
  • Override the global policy on specific views that legitimately need camera or payment APIs.
  • Enforce strict feature restrictions on public-facing pages while relaxing them on authenticated admin areas.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The package is actively maintained, has no known vulnerabilities, integrates seamlessly into Django's middleware stack with low friction, and solves a real security/privacy concern with minimal configuration. Use it if you want to control browser feature access in your Django app.

Install

django-permissions-policy on PyPI

Before you install

Low install friction with a pure Python wheel. Actively maintained with a recent release and straightforward middleware integration into Django's standard stack.

Requires Django 5.2 to 6.1 and Python 3.10 to 3.15.

License in practice

MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects.

Quickstart

# Install
python -m pip install django-permissions-policy

# In settings.py, add to MIDDLEWARE after SecurityMiddleware:
MIDDLEWARE = [
    "django.middleware.security.SecurityMiddleware",
    "django_permissions_policy.PermissionsPolicyMiddleware",
]

# Configure the policy:
PERMISSIONS_POLICY = {
    "geolocation": [],
    "camera": [],
    "microphone": [],
}

# In a view, optionally override:
from django_permissions_policy.decorators import permissions_policy_override

@permissions_policy_override({"camera": ["self"]})
def video_call_view(request):
    pass

Verify before relying

  • Whether the package validates against the full current W3C feature list or relies on browser-reported features
  • Performance impact when processing responses with complex permission policies

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
asgirefdjango
MaintenanceActively maintained 0 days since the last release
Last repo commit
First released
Downloads466,341 / month, #6,504 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableFramework :: Django :: 5.2Framework :: Django :: 6.0Framework :: Django :: 6.1Intended Audience :: DevelopersNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.15Programming Language :: Python :: Implementation :: CPythonTyping :: Typed

Evidence: django_permissions_policy-4.33.0-py3-none-any.whl

Tags

Capabilities
django permissions policy headerbrowser feature policy djangodisable geolocation camera microphonedjango security middlewarepermissions policy middlewarefeature policy enforcementdjango http headers security
Topics
django-middlewarebrowser-securityhttp-headers
PyPI keywords
Django

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “django permissions policy header”

  • django-permissions-policySets the Permissions-Policy HTTP header on Django responses to…
  • drf-access-policyDeclares access control rules for Django REST Framework views using…
  • secureApplies HTTP security headers to Python web responses through a…

Give your agent the search over MCP, or paste the wish link into any chat.

More Dynamic Content packages

MarkupSafe Worth it
PyPI · Dynamic Content · released Sep 2025

MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.

BSD-3-Clausecompiled wheel · 3.9+aging
797.1Mdownloads / mo
Jinja2 Worth it
PyPI · Dynamic Content · released Mar 2025

Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.

BSD-3-Clausepure Python · 3.7+aging
718.6Mdownloads / mo
soupsieve Worth it
PyPI · Python Modules · released Aug 2026

Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.

Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.

MITpure Python · 3.10+
428.6Mdownloads / mo
Werkzeug Worth it
PyPI · Application Frameworks · released Apr 2026

Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.

BSD-3-Clausepure Python · 3.9+
268.1Mdownloads / mo
Flask Worth it
PyPI · Application Frameworks · released Feb 2026

Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.

BSD-3-Clausepure Python · 3.9+
211.4Mdownloads / mo
Mako Worth it
PyPI · Dynamic Content · released Aug 2026

Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.

MITpure Python · 3.10+
201.7Mdownloads / mo

See also django-csp · django-cors-headers · secure · flask-talisman · invenio-records-permissions · Secweb · django-hosts · django-decorator-include · django-browser-reload · django-request-logging