Crea una Content-Security-Policy y fragmentos de cabeceras para Nginx o Apache sin analizar tu sitio.
Paste an existing CSP to inspect it, or use the builder on the right. This tool analyzes only the text you enter.
Enter source expressions without the directive name. Leave a field blank to omit that directive.
Only use HSTS after HTTPS is correctly configured for every relevant subdomain. Review generated values against your application requirements.
Build a CSP, then generate header snippets.
Build a CSP, then generate header snippets.
Build a CSP, then generate header snippets.
A CSP should match the resources your application genuinely needs. Roll it out carefully, consider report-only testing first, and avoid copying a policy between sites without reviewing scripts, frames, APIs, and third-party assets.