New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 850482 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 588970
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Feature



Sign in to add a comment

[Feature Request] Content Security Policy inspector

Reported by lilia...@gmail.com, Jun 7 2018

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36

Steps to reproduce the problem:
1. Open Devtools
2. Select the Security tab

What is the expected behavior?
The effective CSP for the current page is nicely rendered, e.g.:

script-src: 'self' https://example.com;
frame-src: 'none';
default-src: 'self';

What went wrong?
No CSP info shown.

Did this work before? No 

Chrome version: 66.0.3359.181  Channel: n/a
OS Version: OS X 10.11.6
Flash Version: 

CSP is an important web security feature. Due to multiple methods of specifying the CSP (all on one line, in response headers or possibly multiple meta tags), it is difficult to determine what the effective CSP is for a given page. It would be immensely helpful to see the values of all the CSP directives listed in an explicit and readable format, similar to the display of css properties in the Styles section.
 
Labels: Needs-Triage-M66
Cc: sindhu.chelamcherla@chromium.org
Labels: -Type-Bug Triaged-ET M-69 Target-69 FoundIn-69 Type-Feature
Status: Untriaged (was: Unconfirmed)
As per comment#0 this seems to be a feature request. Hence marking as Untriaged.

Thanks!

Comment 3 by kozy@chromium.org, Jun 11 2018

Owner: est...@chromium.org
Status: Assigned (was: Untriaged)
Emily, WDYT?

Comment 4 by est...@chromium.org, Jun 11 2018

Cc: andypaicu@chromium.org
Mergedinto: 588970
Status: Duplicate (was: Assigned)
This would be very cool, and has been requested before, but we don't have the resources to prioritize it right now. +andypaicu in case he might want to pick it up

Sign in to add a comment