CORS Unblock
No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled
Disable Content-Security-Policy for web application testing. When the icon is coloured, CSP headers are disabled.
Review user movement across collected snapshots.
View collected rating snapshots from the latest 7-day window to assess rating stability.
Compare 1-day, 7-day, and 30-day net growth and growth rate.
Review publication date, version, supported languages, and crawl timestamps.
Review the store description, core capabilities, and common use cases.
Use at your own risk. Disables the current page's Content Security Policy. Useful when testing what resources a new third-party tag includes onto the page.
Inspect the latest comments and rating distribution.
Store average score: 3.5. The bars below are calculated from synced review text only, so they may be empty for extensions that have public ratings but no synced comments yet.
Review related products from the Chrome Web Store detail page.
No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled
Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.
Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites
Automatically generate content security policy headers online for any website.
A browser extension to disable http header Content-Security-Policy and html meta Content-Security-Policy
A extension that set csp value empty
works very well 非常好用
Doesn't appear to work. There's a work site I'm having trouble with due to a CSP issue. This extension has no effect in disabling those policies; they still appear in the Chrome console and disable the site.
Doesn't work on latest Chromium.
Failed to eliminate CSP policy 'worker-src: none' restriction.
This doesn't work in Chrome 87. It may have at somepoint in the past, but not now :-(
Solves the problem. It won’t automatically activate which is a plus on security.
Saved my life, great for development testing.
Doesn't work. I tried this on JIRA Tempo TImesheets and didn't work. CSP from app.tempo.io as still blocked.
Don't know if it's just me, but it seems it stopped working recently... It was working perfectly before.
I would like that whitelisting would be enabled! (I only want this for single domain) UPDATE: it stopped working for me in late 2020 :(