ሴኪዩሪቲ እና CSP ቼክ እርስዎ ያሉበት ገጽ የምላሽ አርዕስቶችን አንብቦ ደረጃ ሰጥቷቸዋል - የይዘት ደህንነት ፖሊሲ፣ HSTS፣ ሪፈር-ፖሊሲ፣ ዘር-አቋራጭ ቤተሰብ እና ሌሎችም - ከዚያም CSP መመሪያውን በመመሪያ ይጥሳል እና የሚያዳክሙትን ምንጮች ይሰይማሉ።
Security headers are easy to get wrong and hard to check. The values live on the server, the policies are long single-line strings, and the mistakes are quiet: a Content Security Policy that still allows 'unsafe-inline' looks like a policy but stops almost nothing. The usual answer is to paste your URL into an online scanner, which only works for pages a scanner can reach — not a staging site, not an internal tool, not a page behind a login.
This tool checks the page in front of you, signed in as you are. It reads the document's response headers and gives each one a pass, a warning or a failure with a plain explanation: whether a CSP exists at all, whether HSTS will keep browsers on HTTPS, whether MIME sniffing is off, whether referrers leak full URLs, and what the Cross-Origin-* headers are set to. It also points out headers that give away more than they should, such as Server and X-Powered-By naming your exact framework version.
የCSP ትር የሱ ልብ ነው። The policy is split into directives, every source is colour-coded, and the findings read like a review: 'unsafe-inline' in script-src is marked as a failure, 'unsafe-eval' and wildcard origins as warnings, and data: in script-src as the bypass it is. It knows the rules that trip people up — that 'unsafe-inline' is ignored once a nonce or hash is present, so that case is a warning rather than a failure, and that 'strict-dynamic' replaces host allowlists. Missing directives are called out too: no object-src, no base-uri, no frame-ancestors, no form-action. Policies delivered by meta tag and report-only policies are shown separately, because they behave differently.
The Connection tab covers what HTTPS is actually doing: the TLS handshake, HSTS max-age against the one-year threshold that preloading requires, includeSubDomains and preload flags, and every insecure subresource or form target that undermines an HTTPS page. One thing it does not claim: certificate details. No browser extension can read the certificate chain, issuer or expiry date, so rather than invent them the tool says where to look — the padlock in your address bar, or an external service for the full chain.
CSP፣ HSTS፣ X-Content-ዓይነት-አማራጮች፣ X-ፍሬም-አማራጮች፣ ዋቢ-ፖሊሲ፣ ፍቃዶች-ፖሊሲ እና የዘር-አቋራጭ ቤተሰብ፣ እያንዳንዳቸው ማለፊያ፣ ማስጠንቀቂያ ወይም ውድቀት እና ያለመኖር ምን ማለት እንደሆነ ግልጽ ማብራሪያ አላቸው።
መመሪያው በእያንዳንዱ ምንጭ ቀለም ኮድ ወደተሰጠው መመሪያ ይተነተናል፣ ስለዚህ በ500-ቁምፊ ራስጌ ሕብረቁምፊ ውስጥ ከመደበቅ ይልቅ አደገኛ እሴት ጎልቶ ይታያል።
ባንዲራዎች 'unsafe-inline'፣ 'unsafe-eval'፣ wildcards and data: in script-src — ነገር ግን 'unsafe-inline'ን እንደ ማስጠንቀቂያ የሚቆጥሩት ኖን ወይም ሃሽ አሳሾች ችላ እንዲሉ ሲያደርጋቸው ነው፣ እና 'strict-dynamic' እና report-uri ይመሰክራል።
የነገር-src፣ ቤዝ-ዩሪ፣ ፍሬም-አባቶች ወይም ቅጽ-እርምጃ ያለ መመሪያ እያንዳንዱ ክፍተት የሚተው ልዩ አደጋ አለው፣ ነባሪ-src ቀድሞውንም ከመካከላቸው አንዱን ሲሸፍን ጨምሮ።
HSTS ከፍተኛው ዕድሜ ከአንድ አመት ቅድመ ጭነት ገደብ፣ TLS የመጨባበጥ ጊዜ፣ እና እያንዳንዱ http:// ንዑስ ምንጭ ወይም ቅጽ ኢላማ ከመራጩ ጋር ከተዘረዘረው HTTPS ገጽን የሚያፈርስ።
ራስጌዎች እርስዎ እያዩት ካለው ገጽ፣ ከክፍለ-ጊዜዎ ጋር ይነበባሉ፣ ስለዚህ የውስጥ መሳሪያዎች እና የቅድመ-ምርት ጣቢያዎች መፈተሽ ይችላሉ - ስካነር እንዲደርስበት ምንም አይነት የወል ዩአርኤል የለም።
የማረጋገጫ ዝርዝሩን በእውነተኛው ገጽ ላይ ይራመዱ፡ ከሪፖርት-ብቻ ይልቅ CSP መተግበሩን ያረጋግጡ፣ HSTS ለአንድ አመት ተዘጋጅቷል፣ እና ምንም ነገር አሁንም በ http:// ላይ አይጫንም።
የመስመር ላይ ራስጌ አራሚዎች ይፋዊ ዩአርኤል ያስፈልጋቸዋል። ይህ እየተመለከቱት ያለውን ገጽ ያነባል፣ ስለዚህ ከመሰረታዊ auth ወይም ከቪፒኤን ጀርባ ያለው የዝግጅት አካባቢ እንዲሁ ለመፈተሽ ቀላል ነው።
ረጅም ፖሊሲ ማንኛውንም ነገር የሚገድብ እንደሆነ፣ ወይም 'ደህንነቱ የተጠበቀ-ውስጥ መስመር' እና የዱር ካርድ አስተናጋጅ በጸጥታ ወደ ማስዋቢያነት ቀይረውት እንደሆነ በጨረፍታ ይመልከቱ።
በኮንሶል ውስጥ ከማደን ይልቅ በ HTTPS ገጽ ላይ ከኤለመንት መራጭ ጋር አሁንም ትክክለኛውን ምስል፣ ስክሪፕት ወይም የቅጽ እርምጃ ያግኙ።
የእያንዳንዱ አርእስት ቀኑ ያለፈበት ሪፖርት፣ ዋጋው እና ፍርዱ ከኦዲት ጋር ለማያያዝ፣ ከጥቃቅን ክትትል ወይም ከማክበር መጠይቅ ጋር ይቅዱ።
በDevSuite Pro መትከያ ውስጥ የደህንነት እና የCSP አዶን ጠቅ ያድርጉ። ቼኩ ወዲያውኑ ይሰራል እና ማጠቃለያው ስንት ራስጌዎች እንዳለፉ፣ እንዳስጠነቀቁ ወይም እንደጠፉ ያሳያል።
የራስጌዎች ትሩ እያንዳንዱን የደህንነት ራስጌ ከዋጋው እና ከፍርዱ ጋር ይዘረዝራል። ከዚህ በታች የመረጃ-መግለጫ ቼክ እና የሰነዱ የ CORS ራስጌዎች አሉ።
ለግኝቶች ዝርዝር፣ ከዚያም የተተነተኑ መመሪያዎችን የCSP ትርን ይክፈቱ። ቀይ ምንጮች ውድቀቶች ናቸው, አምበር ሰዎች ለሁለተኛ እይታ ዋጋ ያላቸው ናቸው, አረንጓዴዎች ጠንካራ ፖሊሲን ይጠቀማሉ.
የግንኙነት ትሩ HTTPSን፣ TLS መጨባበጥን፣ HSTSን እና ማንኛውንም የተደባለቀ ይዘትን ይሸፍናል። ለእውቅና ማረጋገጫው ራሱ፣ በአድራሻ አሞሌው ላይ ያለውን ቁልፍ ጠቅ ያድርጉ - ምንም ቅጥያ ሊያነበው አይችልም።
የቅጂ ሪፖርት የእያንዳንዱን ፍርድ፣ የCSP ግኝቶች እና ማንኛውንም የተቀላቀሉ ይዘቶች ለትኬት ወይም ለደህንነት ግምገማ የተዘጋጀ ግልጽ-ጽሁፍ ማጠቃለያ ያወጣል።
DevSuite Pro ን በነፃ ይጫኑ እና 71+ የገንቢ መሳሪያዎችን ለአሳሽዎ ይክፈቱ።