Always Disable Content-Security-Policy
Extension Actions
- No Privacy Policy
- Live on Store
Always Disable Content-Security-Policy for web application testing. When the icon is coloured, CSP headers are disabled.
This is a fork of Phil Grayson's extension with the only difference being that this one disables the headers by default. Original: https://chrome.google.com/webstore/detail/disable-content-security/ieelmcmcagommplceebfedjlakkhpden
Use at your own risk. Disables the current page's Content Security Policy. Useful when testing what resources a new third-party tag includes onto the page.
Click the extension icon to re-enable CSP headers. Click the extension icon again to disable CSP headers.
Use this only as a last resort. Disabling CSP means disabling features designed to protect you from cross-site scripting. Prefer to use report-uri which instructs the browser to send CSP violations to a URI. That allows you keep CSP enabled in your browser but still know what got blocked. https://report-uri.com is a free tool that gives you a web interface to inspect CSP violations on your site.
Latest reviews
- hailong hu
- Very effective
- Jordan Embry
- Only works when I disable then enable and refresh. Doesn't always disable when I want it to. Should be a easy fix. If there was a way to always enable then disable on every refresh it would work as intended.
- V Cizek
- This one works for me, even for using with Luigi project, which loads pages in iframes. Love this extension! Thank you.
- V Cizek
- This one works for me, even for using with Luigi project, which loads pages in iframes. Love this extension! Thank you.
- Nikolay Lanets
- Works. Thanks!
- Nikolay Lanets
- Works. Thanks!
- Matt Keperling
- It no longer works.
- Matt Keperling
- It no longer works.
- PossessWithin
- Excellent, thank you very much!
- PossessWithin
- Excellent, thank you very much!
- Karmylr
- not always disable
- Karmylr
- not always disable
- Jon Anders Sylvarnes
- Does not work
- Jon Anders Sylvarnes
- Does not work
- Vladislav Osaulenko
- It doesn't work for <meta content="...">
- Vladislav Osaulenko
- It doesn't work for <meta content="...">
- Ron Moses
- Doesn't appear to work. There's a work site I'm having trouble with due to a CSP issue. This extension has no effect in disabling those policies; they still appear in the Chrome console and disable the site.
- Ron Moses
- Doesn't appear to work. There's a work site I'm having trouble with due to a CSP issue. This extension has no effect in disabling those policies; they still appear in the Chrome console and disable the site.
- NEA
- its just works. thats what i need
- NEA
- its just works. thats what i need
- Jaime Lozano
- Only CSP plugin that worked. Thanks!
- Jaime Lozano
- Only CSP plugin that worked. Thanks!
- Sam Gurdus
- Works great! Super happy with this extension.
- Sam Gurdus
- Works great! Super happy with this extension.
- Naveen Kumarasinghe
- Very simple and works!
- Naveen Kumarasinghe
- Very simple and works!
- Rudie Dirkx
- Works for Github, which definitely has CSP on. Buttt doesn't work for https://f95zone.to/ which must have CSP on, because my bookmarklet doesn't work, and Chrome complains about a very specific f95zone CSP header. Why?
- Rudie Dirkx
- Works for Github, which definitely has CSP on. Buttt doesn't work for https://f95zone.to/ which must have CSP on, because my bookmarklet doesn't work, and Chrome complains about a very specific f95zone CSP header. Why?
- YASH PAHALAJANI
- It does what is says :100:
- YASH PAHALAJANI
- It does what is says :100: