Item logo image for Disable Content-Security-Policy

Disable Content-Security-Policy

3.5(

100 ratings

)
Item media 1 (screenshot) for Disable Content-Security-Policy

Overview

Disable Content-Security-Policy for web application testing. When the icon is coloured, CSP headers are disabled.

Use at your own risk. Disables the current page's Content Security Policy. Useful when testing what resources a new third-party tag includes onto the page.

Details

  • Version
    4.0.0
  • Updated
    3 September 2024
  • Offered by
    Phil Grayson
  • Size
    29.02KiB
  • Languages
    2 languages
  • Developer
    Email
    phil@philgrayson.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organisation
The developer has disclosed that it will not collect or use your data. To learn more, see the developer's privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

Allow CORS: Access-Control-Allow-Origin

3.4

Easily add (Access-Control-Allow-Origin: *) rule to the response header.

CSP Evaluator

3.1

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

Allow CSP: Content-Security-Policy

4.0

Easily remove CSP (Content-Security-Policy) rules from the response header.

ModHeader - Modify HTTP headers

3.0

Modify HTTP request headers, response headers, and redirect URLs

CORS Unblock

4.1

No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled

Ignore X-Frame headers

4.4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Content Security Policy (CSP) Generator

4.6

Automatically generate content security policy headers online for any website.

Disable-CSP

3.7

A browser extension to disable http header Content-Security-Policy and html meta Content-Security-Policy

Disable Content Security Policy

4.2

A extension that set csp value empty

Requestly: Intercept & Modify HTTP Requests

4.5

Intercept & modify HTTP(S) traffic: redirect URLs, modify headers, inject scripts, mock REST & GraphQL APIs, and more.

CSP Unblock

4.5

No more Content-Security-Policy limitations. This extension removes all CSP-related headers during website testing.

Allow CORS: Access-Control-Allow-Origin

3.4

Easily add (Access-Control-Allow-Origin: *) rule to the response header.

CSP Evaluator

3.1

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

Allow CSP: Content-Security-Policy

4.0

Easily remove CSP (Content-Security-Policy) rules from the response header.

ModHeader - Modify HTTP headers

3.0

Modify HTTP request headers, response headers, and redirect URLs

CORS Unblock

4.1

No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled

Ignore X-Frame headers

4.4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Content Security Policy (CSP) Generator

4.6

Automatically generate content security policy headers online for any website.

Google apps