Disable Content-Security-Policy: изображение логотипа

Disable Content-Security-Policy

3,5(

102 оценки

)
Мультимедийный объект 1 (скриншот) для сервиса "Disable Content-Security-Policy"

Обзор

Disable Content-Security-Policy for web application testing. When the icon is colored, CSP headers are disabled.

Use at your own risk. This disables the Content-Security-Policy header for a tab. Use this when testing what resources a new third-party tag includes onto the page. Click the extension icon to disable Content-Security-Policy header for the tab. Click the extension icon again to re-enable Content-Security-Policy header. Use this only as a last resort. Disabling Content-Security-Policy means disabling features designed to protect you from cross-site scripting. Prefer to use report-uri which instructs the browser to send CSP violations to a URI. That allows you keep Content-Security-Policy enabled in your browser but still know what got blocked. https://report-uri.com is a free tool that gives you a web interface to inspect CSP violations on your site.

Подробности

  • Версия
    4.0.0
  • Обновлено
    3 сентября 2024 г.
  • Автор:
    Phil Grayson
  • Размер
    29.02KiB
  • Языки
    Поддерживаемых языков: 2
  • Разработчик
    Электронная почта
    phil@philgrayson.com
  • Не продавец
    Разработчик не указал для себя статус продавца. Просим клиентов из Европейского союза обратить внимание, что на сделки между вами и этим разработчиком не распространяются законы о защите прав потребителей.

Конфиденциальность

Управляйте расширениями и узнавайте, как они используются в вашей организации.
Разработчик сообщил, что продукт не собирает и не использует ваши данные. Узнать больше можно в правилах разработчика: privacy policy.

Этот разработчик утверждает, что ваши данные:

  • Не продаются третьим лицам, за исключением разрешенных вариантов использования
  • Не используются и не передаются в целях, не связанных с работой основных функций продукта
  • Не используются и не передаются для определения платежеспособности или в целях кредитования

Поддержка

Похожие

Allow CORS: Access-Control-Allow-Origin

3,4

Easily add (Access-Control-Allow-Origin: *) rule to the response header.

CSP Evaluator

3,1

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

Allow CSP: Content-Security-Policy

4,0

Easily remove CSP (Content-Security-Policy) rules from the response header.

Moesif Origin/CORS Changer & API Logger

3,8

Allow cross-domain requests by override Origin and CORS headers. Log/capture XmlHttpRequest API calls for debugging and analytics.

CORS Unblock

4,1

No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled

Ignore X-Frame headers

4,4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Anti-CORS, anti-CSP

4,1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Content Security Policy (CSP) Generator

4,6

Automatically generate content security policy headers online for any website.

Disable-CSP

3,7

A browser extension to disable http header Content-Security-Policy and html meta Content-Security-Policy

Disable Content Security Policy

4,2

A extension that set csp value empty

Requestly: Intercept & Modify HTTP Requests

4,5

Intercept & modify HTTP(S) traffic: redirect URLs, modify headers, inject scripts, mock REST & GraphQL APIs, and more.

CSP Unblock

4,5

No more Content-Security-Policy limitations. This extension removes all CSP-related headers during website testing.

Allow CORS: Access-Control-Allow-Origin

3,4

Easily add (Access-Control-Allow-Origin: *) rule to the response header.

CSP Evaluator

3,1

CSP Evaluator is a tool that allows developers to check if a Content Security Policy (CSP) serves as mitigation against XSS attacks.

Allow CSP: Content-Security-Policy

4,0

Easily remove CSP (Content-Security-Policy) rules from the response header.

Moesif Origin/CORS Changer & API Logger

3,8

Allow cross-domain requests by override Origin and CORS headers. Log/capture XmlHttpRequest API calls for debugging and analytics.

CORS Unblock

4,1

No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled

Ignore X-Frame headers

4,4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

Anti-CORS, anti-CSP

4,1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Content Security Policy (CSP) Generator

4,6

Automatically generate content security policy headers online for any website.

Приложения Google