← 全部工具

@einride/csp-evaluator-cli

热度 65 更新于 开发与构建

A command line tool to validate Content-Security-Policy rules

npmauto-collected

安装

npm
npm install -g @einride/csp-evaluator-cli

通过 npm 安装。

csp-evaluator-cli

A command line tool that wraps [csp-evaluator].

Installation

$ npm install -g @einride/csp-evaluator-cli

Usage

CLI interface strives to mimic [CSP Evaluator online tool]. It takes Content Security Policy as a string, and outputs findings based on that into stdout.

Output format

There are three supported output formats:

  • human (default)

Mimics [CSP Evaluator online tool] output.

> csp validate "script-src https://google.com"
! Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?
script-src:
   ? https://google.com: No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.
  • json

JSON is passed as is from [csp-evaluator] output.

> csp validate --output-format=json "script-src https://google.com"
[{"type":300,"description":"Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?","severity":10,"directive":"object-src"},{"type":305,"description":"No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.","severity":50,"directive":"script-src","value":"https://google.com"}]
  • json-pretty

Same as json, but with indentations.

> csp validate --output-format=json-pretty "script-src https://google.com"
[
    {
        "type": 300,
        "description": "Missing object-src allows the injection of plugins which can execute JavaScript. Can you set it to 'none'?",
        "severity": 10,
        "directive": "object-src"
    },
    {
        "type": 305,
        "description": "No bypass found; make sure that this URL doesn't serve JSONP replies or Angular libraries.",
        "severity": 50,

"value": "https://google.com" } ]