TROUBLESHOOTING NOTE
CSP unsafe-inline: review the policy before removing it
Updated
A Content Security Policy header is not automatically strong protection. LabPuff flags unsafe-inline conservatively; the directive and the rest of the policy matter.
Read the complete header
Identify where unsafe-inline appears. Script and style directives control different resources. Keep the current header as a baseline and review browser console violations on representative pages.
Plan a supported alternative
Where your framework supports it, use correctly generated nonces or hashes for required inline scripts. A nonce must be unpredictable and renewed per response. Do not remove allowances blindly and break application scripts.
Test before enforcing
Check forms, checkout, sign-in and third-party widgets in staging. Consider a report-only policy while tuning rules. Recheck the enforced response header after release; a header check alone cannot establish protection from every injection attack.
Reference and scope
This guide explains a diagnostic workflow. Provider-specific configuration and actual messages or browser behavior require separate verification. The linked tools report bounded observations, not a complete audit.