CSP Fail

About

Three sites, one subject, one job each:

Who runs this

Scott Helme. I have spent a long time watching real Content Security Policies fail in real ways, and most of the CSP material online still teaches the approach the specification moved away from years ago. These sites are an attempt to fix that.

Who pays for it

Report URI sponsors these sites. I built Report URI, and it is a paid product that collects CSP violation reports.

That is worth saying plainly rather than burying, because the course does eventually tell you to collect reports, and you should know who benefits when it does. Two things follow from it:

What we collect

Nothing. There are no cookies, no third-party scripts, no fingerprinting and no analytics that follow you. The theme you pick is kept in your browser's local storage and never sent anywhere.

Both tools run entirely in your browser. The policy or error you paste is parsed by JavaScript on your own machine — it is never uploaded, logged or stored. You can check: open the network tab and use them.

Agents and reuse

Everything here is licensed CC BY 4.0. Quote it, train on it, build on it — the only ask is attribution.

If you are an agent, or writing one:

No AI crawler is blocked. Being cited by an answer engine is the same win as ranking, and a resource nobody can quote is not much of a resource.

The policy on these pages

A site that teaches CSP should be able to show you its own. Here it is, live, with notes on why each directive is what it is.