# Analizzatore Content Security Policy

> Spiega le direttive incollate e individua problemi di configurazione comuni.

[Open tool](https://www.toolcabana.com/it/content-security-policy-analyzer) · [Educazione a privacy e sicurezza](https://www.toolcabana.com/it/category/privacy-and-security-education)

Tool ID: content-security-policy-analyzer. Requested language: it. Description language: it. Complete guide translation: yes.

## Overview (en)

Content Security Policy analyzer splits a pasted CSP into directives and lists each with its values and a review note. It flags 'unsafe-inline', 'unsafe-eval', bare wildcard sources, 'none' combined with other sources, and duplicate directives, and adds rows when object-src, base-uri or frame-ancestors is missing. Results are static heuristics for learning and review.

## Supported tasks (it)

Spiega le direttive incollate e individua problemi di configurazione comuni.

## Steps (it)

1. Incolla l'origine nell'editor di input, oppure carica l'esempio integrato.
2. Controlla il formato di origine prima di eseguire l'operazione.
3. Esegui Analizzatore Content Security Policy, esamina il risultato, poi usa i controlli disponibili per copiare o scaricare.

## Settings

No additional settings.

## Limitations (it)

Gli input CSV/XLSX sono limitati a 10 MB ciascuno, 200 colonne e 20.000 righe; l'output unito è limitato a 20.000 righe. La valutazione di script/filtri JSONPath è disabilitata. Le altre operazioni applicano i controlli visibili e i limiti di testo.

## Example input

```text
default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'
```

## Privacy and connections (it)

Questa operazione elabora i dati di origine nel tuo browser. Copia e download sono azioni esplicite; l'input di origine non viene salvato in un account né in una cronologia.

## Questions (it)

### What happens if a CSP has the same directive twice?

The analyzer marks the repeat as a duplicate and notes that browsers use the first occurrence, so values in the later copy are ignored. Merge the sources into a single directive to make the policy behave as intended.

### Why does the CSP analyzer warn that object-src is missing?

object-src, base-uri and frame-ancestors are checked separately as common hardening directives. If one is absent, a row marked missing suggests reviewing whether an explicit restriction is needed; the check does not account for any default-src fallback.

### Should I paste the full header line including Content-Security-Policy:?

Paste only the policy value. Directives are split on semicolons and the first word of each is read as the directive name, so a header prefix would be treated as the first directive's name. Up to 100 directives are accepted.

### Dove viene elaborato il mio input?

Questa operazione elabora i dati di origine nel tuo browser. Copia e download sono azioni esplicite; l'input di origine non viene salvato in un account né in una cronologia.

### Quali sono i limiti di input?

Gli input CSV/XLSX sono limitati a 10 MB ciascuno, 200 colonne e 20.000 righe; l'output unito è limitato a 20.000 righe. La valutazione di script/filtri JSONPath è disabilitata. Le altre operazioni applicano i controlli visibili e i limiti di testo.

## Related tools

- [File encryption and decryption](https://www.toolcabana.com/it/file-encryption-and-decryption)
- [Password strength estimator](https://www.toolcabana.com/it/password-strength-estimator)
- [Sensitive data masking tool](https://www.toolcabana.com/it/sensitive-data-masking-tool)
- [Certificate signing request decoder](https://www.toolcabana.com/it/certificate-signing-request-decoder)
