field Registered
Verified 2026-09-18 · registry updated
2026-08-28CSP Report-Only
CSP-Report-Only lets a site observe policy violations without blocking the affected resource.
Use report-only mode to discover dependencies before enforcement. Treat reports as untrusted input and move to an enforcing policy after reviewing real traffic.
httpsecuritycspmonitoring
Reference (http)
Content-Security-Policy-Report-Only: default-src 'self'; report-to csp-endpoint
Use report-only mode to discover dependencies before enforcement. Treat reports as untrusted input and move to an enforcing policy after reviewing real traffic.
Common mistakes
- Assuming report-only protects the page or accepting violation reports without limiting their size and content.
IANA registry: http-fields/field-names
Registry reference: Content Security Policy Level 3