Content-Security-Policy-Analyzer
Erkläre eingefügte Direktiven und erkenne häufige Konfigurationsprobleme.
So verwendest du Content-Security-Policy-Analyzer
Content Security Policy analyzer splits a pasted CSP into directives and lists each with its values and a review note. It flags 'unsafe-inline', 'unsafe-eval', bare wildcard sources, 'none' combined with other sources, and duplicate directives, and adds rows when object-src, base-uri or frame-ancestors is missing. Results are static heuristics for learning and review.
- Füge die Quelle in den Eingabe-Editor ein oder lade das integrierte Beispiel.
- Prüfe das Quellformat, bevor du den Vorgang ausführst.
- Führe „Content-Security-Policy-Analyzer“ aus, prüfe die Ausgabe und verwende dann die verfügbaren Bedienelemente zum Kopieren oder Herunterladen.
Was dieses Tool unterstützt
Erkläre eingefügte Direktiven und erkenne häufige Konfigurationsprobleme.
Grenzen und Verarbeitung
CSV/XLSX-Eingaben sind auf jeweils 10 MB, 200 Spalten und 20.000 Zeilen begrenzt; die verbundene Ausgabe ist auf 20.000 Zeilen begrenzt. Die Auswertung von JSONPath-Skripten/-Filtern ist deaktiviert. Andere Vorgänge unterliegen ihren sichtbaren Bedienelementen und Textlimits.
Beispielquelle
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'
Häufige Fragen
What happens if a CSP has the same directive twice?
The analyzer marks the repeat as a duplicate and notes that browsers use the first occurrence, so values in the later copy are ignored. Merge the sources into a single directive to make the policy behave as intended.
Why does the CSP analyzer warn that object-src is missing?
object-src, base-uri and frame-ancestors are checked separately as common hardening directives. If one is absent, a row marked missing suggests reviewing whether an explicit restriction is needed; the check does not account for any default-src fallback.
Should I paste the full header line including Content-Security-Policy:?
Paste only the policy value. Directives are split on semicolons and the first word of each is read as the directive name, so a header prefix would be treated as the first directive's name. Up to 100 directives are accepted.
Wo wird meine Eingabe verarbeitet?
Dieser Vorgang verarbeitet seine Quelle in deinem Browser. Kopieren und Herunterladen sind ausdrückliche Aktionen; die Quelleingabe wird nicht in einem Konto oder Verlauf gespeichert.
Welche Eingabelimits gelten?
CSV/XLSX-Eingaben sind auf jeweils 10 MB, 200 Spalten und 20.000 Zeilen begrenzt; die verbundene Ausgabe ist auf 20.000 Zeilen begrenzt. Die Auswertung von JSONPath-Skripten/-Filtern ist deaktiviert. Andere Vorgänge unterliegen ihren sichtbaren Bedienelementen und Textlimits.