Description from extension meta
Always Disable Content-Security-Policy for web application testing. When the icon is colored, CSP headers are disabled.
Image from store
Description from store
This is a fork of Phil Grayson's extension with the only difference being that this one disables the headers by default. Original: https://chrome.google.com/webstore/detail/disable-content-security/ieelmcmcagommplceebfedjlakkhpden
Use at your own risk. Disables the current page's Content Security Policy. Useful when testing what resources a new third-party tag includes onto the page.
Click the extension icon to re-enable CSP headers. Click the extension icon again to disable CSP headers.
Use this only as a last resort. Disabling CSP means disabling features designed to protect you from cross-site scripting. Prefer to use report-uri which instructs the browser to send CSP violations to a URI. That allows you keep CSP enabled in your browser but still know what got blocked. https://report-uri.com is a free tool that gives you a web interface to inspect CSP violations on your site.
Latest reviews
- (2023-08-10) V Cizek: This one works for me, even for using with Luigi project, which loads pages in iframes. Love this extension! Thank you.
- (2023-08-02) Nikolay Lanets: Works. Thanks!
- (2022-12-08) Matt Keperling: It no longer works.
- (2022-09-24) PossessWithin: Excellent, thank you very much!
- (2022-02-17) Karmylr: not always disable
- (2022-02-16) Jon Anders Sylvarnes: Does not work
- (2021-04-13) Vladislav Osaulenko: It doesn't work for <meta content="...">
- (2021-04-13) Ron Moses: Doesn't appear to work. There's a work site I'm having trouble with due to a CSP issue. This extension has no effect in disabling those policies; they still appear in the Chrome console and disable the site.
- (2020-12-11) NEA: its just works. thats what i need
- (2020-11-13) Jaime Lozano: Only CSP plugin that worked. Thanks!
- (2020-10-30) Sam Gurdus: Works great! Super happy with this extension.
- (2020-09-27) Naveen Kumarasinghe: Very simple and works!
- (2020-09-02) Rudie Dirkx: Works for Github, which definitely has CSP on. Buttt doesn't work for https://f95zone.to/ which must have CSP on, because my bookmarklet doesn't work, and Chrome complains about a very specific f95zone CSP header. Why?
- (2020-08-15) YASH PAHALAJANI: It does what is says :100: