top | item 40820252

Intro to CSP report-to and report-URI HTTP headers

3 points| alligatorplum | 1 year ago |kevinpatel.xyz

2 comments

order
[+] theandrewbailey|1 year ago|reply
I have a strict CSP with report-URI on my blog, but all the reports I get are from obscure browser extensions injecting CSS and JS into my pages.
[+] alligatorplum|1 year ago|reply
Yes that is one thing I have learned that there can be a lot of noise from these CSP violation reports. I have found that setting up some alerts for particular resources seems to help suppress some of the noise.