Skip to tool
ecech.
💻 Developer & Code

Put Every CSP Directive on Its Own Review Line

Make long security policy strings readable without claiming to prove safety.

Local result

Input characters

Processing

Browser only

Advertisement

How the calculation works

Pasted inputYour browserTransparent transformNo uploadReviewable outputCopy when ready

How to Use This Tool

Make long security policy strings readable without claiming to prove safety. Format a pasted Content-Security-Policy header locally into one directive per line for manual security review.

The failure CSP Formatter is designed to catch

Formatting reveals duplicates and omissions, but only application-specific testing can show whether a policy is both safe and functional. The boundary is the job stated in Put Every CSP Directive on Its Own Review Line; CSP Formatter is not intended to score or transform a different workflow.

Recorded inputsNamed operationChecked output
The executable example for CSP Formatter expects out: default-src: 'self' img-src: 'self' data: object-src: 'none'; changing an input must produce a correspondingly reviewable result.

The CSP Formatter input contract

The fields used for this specific operation are Input text, Unused option. Keep the source values beside the CSP Formatter result, because replacing the original would remove the evidence needed to reproduce or reverse the operation.

  • For CSP Formatter, Input text starts at default-src 'self'; img-src 'self' data:; object-src 'none' in the worked case; replace that example with the matching source value.
  • For CSP Formatter, Unused option starts at in the worked case; replace that example with the matching source value.

Worked result for CSP Formatter

The executable case called Default browser-only example expects out: default-src: 'self' img-src: 'self' data: object-src: 'none'. Verify that observation before entering real material, and then change one CSP Formatter field at a time so an unexpected direction or formatting change can be traced to a specific input.

Reading the CSP Formatter output

No. The transform runs in browser JavaScript and the page does not call a processing API. Network extensions or a compromised device remain outside this page's control. Apply that answer only when Input text, Unused option describe the same scope and format as the worked operation. If the source uses different units, quoting, nesting, timing or account rules, a plausible-looking CSP Formatter output is not sufficient validation.

Assumptions attached to CSP Formatter

  • CSP Formatter assumes that the pasted input uses the syntax described by the selected standard or page guidance.
  • CSP Formatter assumes that the operation is intentionally narrow and does not infer private downstream schema rules.

If one of these CSP Formatter assumptions is false, keep the result as a diagnostic rather than production or decision data, and choose an implementation that explicitly supports the missing rule.

Evidence maintained for CSP Formatter

The recorded reference is IETF RFC 9110 — HTTP Semantics. Reopen that source when the definition, format, fee or policy behind CSP Formatter changes; private configuration and downstream acceptance still have to be checked in the user's own system.

Where CSP Formatter runs

The named operation executes in browser JavaScript without an ecech calculation API. For CSP Formatter, local execution reduces transmission but does not control browser extensions, device security or the destination where the result is pasted, so sensitive inputs still require the user's normal handling rules.

Sources & assumptions

Tool Spec v2 · verified 2026-08-19. Platform rules and fees can change; the editable inputs remain authoritative for your account.

Official references

Model assumptions

  • The pasted input uses the syntax described by the selected standard or page guidance.
  • The operation is intentionally narrow and does not infer private downstream schema rules.
Advertisement

Frequently Asked Questions

What specific job does CSP Formatter perform?
The CSP Formatter scope is: Format a pasted Content-Security-Policy header locally into one directive per line for manual security review. Anything beyond that stated operation needs a separate model or validator.
Which inputs determine the CSP Formatter result?
For CSP Formatter, the visible inputs are Input text, Unused option; their units, format and reporting scope must match the case being tested.
What result does the CSP Formatter example verify?
The CSP Formatter executable case expects out: default-src: 'self' img-src: 'self' data: object-src: 'none', which is a regression check for this operation rather than an industry benchmark.
What problem should CSP Formatter prevent?
Formatting reveals duplicates and omissions, but only application-specific testing can show whether a policy is both safe and functional.
Which source should I check for CSP Formatter?
The CSP Formatter reference is IETF RFC 9110 — HTTP Semantics; reopen it when the underlying format, policy or definition changes.
Does CSP Formatter send input to a server?
No ecech. calculation API receives the values used by CSP Formatter; browser extensions, the local device and any destination where you paste the result remain separate risks.

Related tools in Developer & Code

Browse all Developer & Code tools
The person who builds ecech., at the desk where the tools are written.

Made by one person

ecech. is not a content farm. Every tool here is written and checked by hand, one at a time, by someone who wanted the tool to exist and could not find a version that showed its working.

No accounts and no sign-in, and nothing you type reaches a server — every calculation on this page runs inside your browser. The ads are served by Google and do set their own cookies, which is set out in full on the privacy page. More about the site.