Build a Content Security Policy without hand-writing every directive. Choose a preset, tune allowed sources, enable report-only mode, and instantly generate a header string, meta tag, Nginx snippet, and JavaScript server config.
Start with a preset, then adjust directives and sources. The policy preview updates live as you change settings.
'unsafe-inline', 'unsafe-eval', *, and broad data/blob allowances so the tradeoffs stay visible.
Switch views and copy exactly what you need for deployment or testing.