{"id":317914,"date":"2025-01-08T13:48:22","date_gmt":"2025-01-08T12:48:22","guid":{"rendered":"https:\/\/glosarix.com\/glossary\/x-content-security-policy-report-only-en\/"},"modified":"2025-03-15T10:26:12","modified_gmt":"2025-03-15T09:26:12","slug":"x-content-security-policy-report-only-en","status":"publish","type":"glossary","link":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/","title":{"rendered":"X-Content-Security-Policy-Report-Only"},"content":{"rendered":"<p>Description: The X-Content-Security-Policy-Report-Only is an HTTP header that allows developers to test their content security policy (CSP) without strictly enforcing it. This approach is particularly useful for logging security violations that may occur in a web application. By implementing this policy, developers can receive reports on any attempts to load content that does not comply with the guidelines set in their CSP, without affecting the site&#8217;s functionality. This allows them to identify vulnerabilities and adjust their security policy before applying it definitively. The policy is configured using the &#8216;Content-Security-Policy-Report-Only&#8217; header, which enables browsers to send reports to a specified URL whenever a violation is detected. This observability mechanism is crucial for enhancing the security of web applications, as it provides valuable insights into how content behaves in the production environment, allowing developers to make informed and proactive adjustments to their CSP.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Description: The X-Content-Security-Policy-Report-Only is an HTTP header that allows developers to test their content security policy (CSP) without strictly enforcing it. This approach is particularly useful for logging security violations that may occur in a web application. By implementing this policy, developers can receive reports on any attempts to load content that does not comply [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"glossary-categories":[],"glossary-tags":[],"glossary-languages":[],"class_list":["post-317914","glossary","type-glossary","status-publish","hentry"],"post_title":"X-Content-Security-Policy-Report-Only ","post_content":"Description: The X-Content-Security-Policy-Report-Only is an HTTP header that allows developers to test their content security policy (CSP) without strictly enforcing it. This approach is particularly useful for logging security violations that may occur in a web application. By implementing this policy, developers can receive reports on any attempts to load content that does not comply with the guidelines set in their CSP, without affecting the site's functionality. This allows them to identify vulnerabilities and adjust their security policy before applying it definitively. The policy is configured using the 'Content-Security-Policy-Report-Only' header, which enables browsers to send reports to a specified URL whenever a violation is detected. This observability mechanism is crucial for enhancing the security of web applications, as it provides valuable insights into how content behaves in the production environment, allowing developers to make informed and proactive adjustments to their CSP.","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>X-Content-Security-Policy-Report-Only - Glosarix<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"X-Content-Security-Policy-Report-Only - Glosarix\" \/>\n<meta property=\"og:description\" content=\"Description: The X-Content-Security-Policy-Report-Only is an HTTP header that allows developers to test their content security policy (CSP) without strictly enforcing it. This approach is particularly useful for logging security violations that may occur in a web application. By implementing this policy, developers can receive reports on any attempts to load content that does not comply [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/\" \/>\n<meta property=\"og:site_name\" content=\"Glosarix\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-15T09:26:12+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@GlosarixOficial\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/\",\"url\":\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/\",\"name\":\"X-Content-Security-Policy-Report-Only - Glosarix\",\"isPartOf\":{\"@id\":\"https:\/\/glosarix.com\/en\/#website\"},\"datePublished\":\"2025-01-08T12:48:22+00:00\",\"dateModified\":\"2025-03-15T09:26:12+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\/\/glosarix.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"X-Content-Security-Policy-Report-Only\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/glosarix.com\/en\/#website\",\"url\":\"https:\/\/glosarix.com\/en\/\",\"name\":\"Glosarix\",\"description\":\"T\u00e9rminos tecnol\u00f3gicos - Glosarix\",\"publisher\":{\"@id\":\"https:\/\/glosarix.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/glosarix.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/glosarix.com\/en\/#organization\",\"name\":\"Glosarix\",\"url\":\"https:\/\/glosarix.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/glosarix.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/glosarix.com\/wp-content\/uploads\/2025\/04\/Glosarix-logo-192x192-1.png.webp\",\"contentUrl\":\"https:\/\/glosarix.com\/wp-content\/uploads\/2025\/04\/Glosarix-logo-192x192-1.png.webp\",\"width\":192,\"height\":192,\"caption\":\"Glosarix\"},\"image\":{\"@id\":\"https:\/\/glosarix.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/GlosarixOficial\",\"https:\/\/www.instagram.com\/glosarixoficial\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"X-Content-Security-Policy-Report-Only - Glosarix","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/","og_locale":"en_US","og_type":"article","og_title":"X-Content-Security-Policy-Report-Only - Glosarix","og_description":"Description: The X-Content-Security-Policy-Report-Only is an HTTP header that allows developers to test their content security policy (CSP) without strictly enforcing it. This approach is particularly useful for logging security violations that may occur in a web application. By implementing this policy, developers can receive reports on any attempts to load content that does not comply [&hellip;]","og_url":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/","og_site_name":"Glosarix","article_modified_time":"2025-03-15T09:26:12+00:00","twitter_card":"summary_large_image","twitter_site":"@GlosarixOficial","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/","url":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/","name":"X-Content-Security-Policy-Report-Only - Glosarix","isPartOf":{"@id":"https:\/\/glosarix.com\/en\/#website"},"datePublished":"2025-01-08T12:48:22+00:00","dateModified":"2025-03-15T09:26:12+00:00","breadcrumb":{"@id":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/glosarix.com\/en\/glossary\/x-content-security-policy-report-only-en\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/glosarix.com\/en\/"},{"@type":"ListItem","position":2,"name":"X-Content-Security-Policy-Report-Only"}]},{"@type":"WebSite","@id":"https:\/\/glosarix.com\/en\/#website","url":"https:\/\/glosarix.com\/en\/","name":"Glosarix","description":"T\u00e9rminos tecnol\u00f3gicos - Glosarix","publisher":{"@id":"https:\/\/glosarix.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/glosarix.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/glosarix.com\/en\/#organization","name":"Glosarix","url":"https:\/\/glosarix.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/glosarix.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/glosarix.com\/wp-content\/uploads\/2025\/04\/Glosarix-logo-192x192-1.png.webp","contentUrl":"https:\/\/glosarix.com\/wp-content\/uploads\/2025\/04\/Glosarix-logo-192x192-1.png.webp","width":192,"height":192,"caption":"Glosarix"},"image":{"@id":"https:\/\/glosarix.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/GlosarixOficial","https:\/\/www.instagram.com\/glosarixoficial\/"]}]}},"_links":{"self":[{"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary\/317914","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/comments?post=317914"}],"version-history":[{"count":0,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary\/317914\/revisions"}],"wp:attachment":[{"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/media?parent=317914"}],"wp:term":[{"taxonomy":"glossary-categories","embeddable":true,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary-categories?post=317914"},{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary-tags?post=317914"},{"taxonomy":"glossary-languages","embeddable":true,"href":"https:\/\/glosarix.com\/en\/wp-json\/wp\/v2\/glossary-languages?post=317914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}