./prontouso.com
BẢO MẬT & RIÊNG TƯ

Trình Tạo Header Content Security Policy (CSP)

Tạo các chỉ thị Content Security Policy (CSP) chuẩn (default-src, script-src, style-src, img-src, connect-src, frame-ancestors) giúp bảo vệ trang web của bạn khỏi các cuộc tấn công tiêm mã độc (XSS) và chèn khung lừa đảo (clickjacking).

Trạng thái công cụChạy trên trình duyệt của bạn
Xem trước
prontouso://security/csp-generator
HEADER · NGINX · APACHE · METAAUTO GENERATE

Start from a profile

Pick a starting point, then fine-tune each directive below. Switching profiles keeps whatever you've already typed in directives it doesn't mention.

POLICY
default-src
Fallback source list for any directive not set explicitly below.
'self'
Quick add
script-src
Where JavaScript may be loaded and executed from.
'self'
Quick add
style-src
Where stylesheets and inline <style> may come from.
'self'
Quick add
img-src
Where images may be loaded from.
'self'data:
Quick add
font-src
Where @font-face fonts may be loaded from.
'self'
Quick add
connect-src
Allowed targets for fetch, XHR, WebSocket and EventSource.
'self'
Quick add
worker-src
Where Worker/SharedWorker/ServiceWorker scripts may load from.
Off — the browser uses the applicable fallback, when this directive has one.
frame-src
Allowed sources for embedded <frame>/<iframe> content.
'none'
Quick add
object-src
Allowed sources for <object>/<embed>/<applet>. Leave at 'none' unless you need Flash-era plugins.
'none'
Quick add
base-uri
Restricts what a <base> tag is allowed to point to, blocking a common injection trick.
'self'
Quick add
form-action
Allowed targets for HTML form submissions.
'self'
Quick add
frame-ancestors
Who may embed this page in a frame — the CSP replacement for X-Frame-Options.
'none'
Quick add
Violation reporting
● NO LOGIN · PROCESSED LOCALLY

Generated policy

Pick the format that matches where you're deploying this.

ĐẦU RA
Policy health

Automatic checks against common CSP mistakes.

✓No obvious weaknesses found in the enabled directives.
HTTP header
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none';
Test an origin

Check whether a given URL would be allowed under the directive you pick, using the policy above.

Resource type
URL to test
Rollout checklist
1. Ship this Report-Only header — nothing on the site breaks yet.
2. Collect reports for several days of real traffic before touching anything.
3. Adjust the directives above for any legitimate resource that shows up blocked.
4. Once reports come back clean, switch the mode to Enforce.

Cách thức hoạt động

  1. Nhập dữ liệu của bạn

    Điền các giá trị cần thiết, dán văn bản hoặc tải lên tệp bạn muốn xử lý.

  2. Xem kết quả tức thì

    Hầu hết các công cụ cập nhật theo thời gian thực khi bạn nhập liệu; một số công cụ sử dụng một nút hành động duy nhất.

  3. Sử dụng kết quả

    Sao chép, tải xuống hoặc chia sẻ kết quả được tạo — bạn luôn có toàn quyền kiểm soát dữ liệu của mình.

Quyền riêng tư & xử lý dữ liệu — Chạy cục bộ 100% trên trình duyệt của bạn. Công cụ này không tải dữ liệu của bạn lên máy chủ.

Trình Tạo Header Content Security Policy (CSP) là gì?

Trình tạo Header CSP hỗ trợ lập trình viên xây dựng chính sách bảo mật nội dung chặt chẽ, tối ưu SEO và an toàn cho website.

TÌM HIỂU CÁCH HOẠT ĐỘNG CỦA CÔNG CỤ

Hướng Dẫn Tạo & Cấu Hình Header Content Security Policy (CSP)

Tìm hiểu cách tạo và thiết lập Header Content Security Policy (CSP) giúp bảo vệ trang web khỏi nguy cơ tấn công Cross-Site Scripting (XSS).

4 Cấu Hình CSP Mẫu Chuẩn Bảo Mật

Chọn nhanh 1 trong 4 mẫu cấu hình: "Khởi đầu" (cho website truyền thống), "SPA" (cho ứng dụng đơn trang React/Vue), "Strict (nonce)" (sử dụng mã nonce chống XSS nâng cao), và "Khóa chặt" (mức độ bảo mật tối đa).

Phân Loại Chỉ Thị & Định Dạng Cú Pháp Header

Tùy chỉnh dễ dàng các chỉ thị default-src, script-src, style-src, img-src, connect-src. Kết quả mã sẽ tự động xuất ra định dạng Header HTTP hoặc thẻ Meta HTML.

Thử Nghiệm Chính Sách Không Gây Lỗi

Bạn có thể thử nghiệm CSP bằng header Content-Security-Policy-Report-Only để ghi nhận báo cáo lỗi vi phạm mà không làm gián đoạn tính năng website.

Bảo mật cấu hình tuyệt đối

Mọi thiết lập chỉ thị CSP được xử lý hoàn toàn trên thiết bị cá nhân của bạn.

Các Câu Hỏi Thường Gặp (FAQ)

Header Content Security Policy (CSP) giúp bảo vệ website thế nào?

CSP ngăn chặn các cuộc tấn công chèn mã độc Cross-Site Scripting (XSS) bằng cách chỉ cho phép trình duyệt tải và thực thi tài nguyên từ các nguồn tin cậy được khai báo.

Nên dùng Header HTTP CSP hay thẻ Meta HTML?

Khuyến nghị sử dụng Header HTTP từ máy chủ vì hỗ trợ đầy đủ tất cả các chỉ thị bảo mật (như frame-ancestors) tốt hơn thẻ Meta trong HTML.

Làm sao để thử nghiệm CSP mà không gây lỗi giao diện website?

Hãy sử dụng header Content-Security-Policy-Report-Only. Chế độ này không chặn tài nguyên vi phạm mà chỉ ghi nhận báo cáo lỗi giúp bạn tinh chỉnh trước khi chặn thực tế.

Công Cụ Liên Quan