Build a Content-Security-Policy header with a readable directive editor.
Test a policy in report-only mode before enforcing it in production.
Usage
Add allowed sources to each directive, then copy the policy into your server configuration. Test in report-only mode first.
Privacy
Policies are generated locally.