Bỏ qua tới nội dung chính

Thiết kế kiểm soát · Công cụ 07

CSP Workbench

Parse policy theo directive, tìm fallback/wildcard/unsafe source và dựng lộ trình Report-Only → Enforce kèm header có thể dùng thực tế.

Trình duyệt10–15 phút

CSP workbench

Analyze → Build → Deploy

Có thể dán cả prefix Content-Security-Policy:. Multiple header policies cần review riêng vì chúng combine restrictively.

Normalized (first directive wins)

default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'
Info

Chưa cấu hình CSP reporting

Violation report giúp rollout dựa trên evidence. report-uri vẫn hữu ích làm fallback cho browser cũ. Fix: Dùng Reporting-Endpoints + report-to; cân nhắc report-uri fallback.

Observed good

Không thấy lỗi baseline rõ ràng

Vẫn cần chạy Report-Only và review violation trên các route/role khác nhau.

Parser dùng browser semantics first-directive-wins và effective fallback; không chấm điểm giả.