DevTool: Remove CSP, IFrame option
Attention. This extension only for web developers. Disables the Security Policy of the contents of the current one-click page for testing web applications. The tool is designed for developers. Use at your own risk. Turn the СSP headers on and off with one click on the icon. What CSP is it? Content Security Policy (CSP) is a computer security standard introduced to prevent cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. It is a Candidate Recommendation of the W3C working group on Web Application Security, widely supported by modern web browsers. CSP provides a standard method for website owners to declare approved origins of content that browsers should be allowed to load on that website—covered types are JavaScript, CSS, HTML frames, web workers, fonts, images, embeddable objects such as Java applets, ActiveX, audio and video files, and other HTML5 features. This extension can remove or modify this headers: ACCESS-CONTROL-ALLOW-ORIGIN ACCESS-CONTROL-ALLOW-METHODS X-WEBKIT-CSP X-FRAME-OPTIONS CONTENT-SECURITY-POLICY-REPORT-ONLY CONTENT-SECURITY-POLICY X-CONTENT-SECURITY-POLICY
查看更多
评论
全部评论
展开更多评论