Updated
Using Content Security Policy builder
Content Security Policy builder accepts explicit HTTPS origins and generates separate directives. It rejects paths and injected directives instead of silently broadening the policy.
A worked example
An empty origin list allows same-origin scripts, styles, images, fonts and connections while setting default-src to none.
Before you use the result
This is a starting policy, not a security audit. It does not support inline code, nonces, hashes, workers or frames. Report-only does not block resources and no reporting endpoint is configured. Validate it against your application before enforcement.
Cite this page
ToolOctopus. “Content Security Policy builder.” Updated 2026-09-19. https://tooloctopus.com/content-security-policy-builder.
Add an access date if your instructions require one.
Citation formatting uses citeproc-js by Frank Bennett and Citation Style Language styles. Licence and source code.
