csp-evaluator-cli
A command line tool that wraps [csp-evaluator].
Installation
$ npm install -g @einride/csp-evaluator-cliUsage
CLI interface strives to mimic [CSP Evaluator online tool]. It takes Content Security Policy as a string, and outputs findings based on that into stdout.
Output format
There are three supported output formats:
- human (default)
Mimics [CSP Evaluator online tool] output.
> csp validate "script-src https://google.com"
! Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?
script-src:
? https://google.com: No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.- json
JSON is passed as is from [csp-evaluator] output.
> csp validate --output-format=json "script-src https://google.com"
[{"type":300,"description":"Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?","severity":10,"directive":"object-src"},{"type":305,"description":"No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.","severity":50,"directive":"script-src","value":"https://google.com"}]- json-pretty
Same as json, but with indentations.
> csp validate --output-format=json-pretty "script-src https://google.com"
[
{
"type": 300,
"description": "Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?",
"severity": 10,
"directive": "object-src"
},
{
"type": 305,
"description": "No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.",
"severity": 50,"value": "https://google.com" } ]