By problem

Solutions

Five problems people arrive with, and what a Content Security Policy with reporting actually does about each one. Every page follows the same order: what the attack is, what the browser reports when it happens, what HeaderHawk does with that report, and where CSP alone is not enough.

What these pages are not claiming

HeaderHawk receives violation reports. It is not in your visitors' request path, it does not run on your pages, and it blocks nothing — when something is blocked, it is your own policy header doing it, in the visitor's browser. Report-only mode, which is where every rollout starts, blocks nothing at all by design. Read each page as a description of what becomes visible, not of what becomes impossible.