ToolCabana

Analisador de Política de Segurança de Conteúdo (CSP)

Explica diretivas coladas e identifica problemas comuns de configuração.

Favorites are saved in this browser. Find them in My favorites.

Analisador de Política de Segurança de Conteúdo (CSP)

Your input stays in this browser unless stated otherwise
Clear your input, files and result, and restore the default settings.
Load sample text to explore what this tool can do. This replaces your current input.
0 charactersClear the source text.

Como usar Analisador de Política de Segurança de Conteúdo (CSP)

Content Security Policy analyzer splits a pasted CSP into directives and lists each with its values and a review note. It flags 'unsafe-inline', 'unsafe-eval', bare wildcard sources, 'none' combined with other sources, and duplicate directives, and adds rows when object-src, base-uri or frame-ancestors is missing. Results are static heuristics for learning and review.

  1. Cole a fonte no editor de entrada ou carregue o exemplo integrado.
  2. Verifique o formato de origem antes de executar a operação.
  3. Execute o analisador de Política de Segurança de Conteúdo (CSP), revise a saída e use os controles disponíveis para copiar ou baixar.

O que esta ferramenta suporta

Explica diretivas coladas e identifica problemas comuns de configuração.

Limites e processamento

As entradas CSV/XLSX são limitadas a 10 MB cada, 200 colunas e 20,000 linhas; a saída combinada é limitada a 20,000 linhas. A avaliação de scripts/filtros JSONPath está desativada. Outras operações aplicam seus controles visíveis e limites de texto.

Fonte de exemplo
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

Perguntas frequentes

What happens if a CSP has the same directive twice?

The analyzer marks the repeat as a duplicate and notes that browsers use the first occurrence, so values in the later copy are ignored. Merge the sources into a single directive to make the policy behave as intended.

Why does the CSP analyzer warn that object-src is missing?

object-src, base-uri and frame-ancestors are checked separately as common hardening directives. If one is absent, a row marked missing suggests reviewing whether an explicit restriction is needed; the check does not account for any default-src fallback.

Should I paste the full header line including Content-Security-Policy:?

Paste only the policy value. Directives are split on semicolons and the first word of each is read as the directive name, so a header prefix would be treated as the first directive's name. Up to 100 directives are accepted.

Onde minha entrada é processada?

Esta operação processa sua fonte no seu navegador. Copiar e baixar são ações explícitas; a entrada de origem não é salva em conta nem em histórico.

Quais são os limites de entrada?

As entradas CSV/XLSX são limitadas a 10 MB cada, 200 colunas e 20,000 linhas; a saída combinada é limitada a 20,000 linhas. A avaliação de scripts/filtros JSONPath está desativada. Outras operações aplicam seus controles visíveis e limites de texto.