3bacf54b6a23bc56f728c2e670c9b2cca96222dd
max
  Wed Sep 16 04:56:02 2026 -0700
htmshell: drop the two CSP response-header helpers that no longer have callers, refs #38353

cspWriteResponseHeader() was their only user and it queues the policy through
cgiAddHttpHeader() now, so generateCspResponseHeader() and getCspMetaResponseHeader() build a
header line nothing sends.  Neither had another caller at any point.  The meta-tag side is
untouched.

diff --git src/lib/htmshell.c src/lib/htmshell.c
index d8655157a9e..cefcb2de0e0 100644
--- src/lib/htmshell.c
+++ src/lib/htmshell.c
@@ -1097,66 +1097,47 @@
 dyStringAppend(policy, " stats.g.doubleclick.net"); // used by google analytics
 dyStringAppend(policy, ";");
 */
 return dyStringCannibalize(&policy);
 }
 
 char *getCspMetaString(char *policy)
 /* get the policy string as an html header meta tag */
 {
 char meta[4096];
 safef(meta, sizeof meta, "<meta http-equiv='Content-Security-Policy' content=\"%s\">\n", policy); 
 // use double quotes around policy because it contains single-quoted values.
 return cloneString(meta);
 }
 
-char *getCspMetaResponseHeader(char *policy)
-/* get the policy string as an http response header */
-{
-char response[4096];
-safef(response, sizeof response, "Content-Security-Policy: %s\n", policy); 
-return cloneString(response);
-}
-
 char *getCspMetaHeader()
 /* return meta CSP header string */
 {
 char *policy = getCspPolicyString();
 char *meta = getCspMetaString(policy);
 freeMem(policy);
 return meta;
 }
 
 void generateCspMetaHeader(FILE *f)
 /* generate meta CSP header */
 {
 char *meta = getCspMetaHeader();
 fputs(meta, f);
 freeMem(meta);
 }
 
-void generateCspResponseHeader(FILE *f)
-/* generate the CSP as an http response header.  Carries the same nonce as the
- * meta tag, since getNonce() is one-per-process, so a page may safely have both.
- * Must be called before the blank line that ends the http header block. */
-{
-char *policy = getCspPolicyString();
-char *header = getCspMetaResponseHeader(policy);
-fputs(header, f);
-freeMem(header);
-freeMem(policy);
-}
 
 
 void _htmStartWithHead(FILE *f, char *head, char *title, boolean printDocType, int dirDepth)
 /* Write out bits of header that both stand-alone .htmls
  * and CGI returned .htmls need, including optional head info */
 {
 if (printDocType)
     fputs("<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\" "
           "\"http://www.w3.org/TR/html4/loose.dtd\">\n",f);
 
 if (doNotTranslate)
     fputs("<HTML lang='en' class='notranslate' translate='no'>\n", f); // switches off auto-translation question
 else
     fputs("<HTML>\n", f);