{"id":11309447,"date":"2019-03-13T17:53:27","date_gmt":"2019-03-13T17:53:27","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/is-it-possible-to-unset-or-remove-csp-header-in-admin-area\/"},"modified":"2019-03-13T17:54:13","modified_gmt":"2019-03-13T17:54:13","slug":"is-it-possible-to-unset-or-remove-csp-header-in-admin-area","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/is-it-possible-to-unset-or-remove-csp-header-in-admin-area\/","title":{"rendered":"Is it possible to unset or remove CSP header in admin area?"},"content":{"rendered":"<p>Hi Guys,<br \/>\nIs it possible to unset or remove the Content Security Policy header in the WP admin area via functions?<\/p>\n<p>I&#8217;ve tried everything I can find &#8211; ie. header_remove, header_unset, etc.<\/p>\n<p>I&#8217;ve tried &lt;location . . .&gt; based.<\/p>\n<p>As it is, the CSP header is a real bugger to implement on WP. You can get it working &#8220;ok&#8221; on the front-end. But once you log in to the admin area then damn near everything is broken by it.<\/p>\n<p>I&#8217;ve decided I have a love-hate relationship with the CSP header at this point. Especially on WP with all of the inline js and css in WP core, themes and plugins. Nonce is a royal pain to set up and easily hacked if done incorrectly. Hashes are easy to set up but will instantly break as soon the the theme, plugin or core changes.<\/p>\n<p>At the moment I have mine set in &#8220;report only&#8221; mode to see if I can work it out in any way without the &#8220;unsafe&#8221; directive. Otherwise, &#8220;unsafe&#8221; defeats the whole purpose.<\/p>\n<p>By the way, my server is Apache with Nginx &#8211; PHP 7.3.3 running FPM application served by Nginx. &#8212; This means removing this header in admin area via htaccess is not an option.<\/p>\n<p>I appreciate any and all feedback you have on this.<\/p>\n<p>Thank you!<br \/>\nLL<\/p>\n","protected":false},"template":"","class_list":["post-11309447","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/11309447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/11309447\/revisions"}],"predecessor-version":[{"id":11309453,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/11309447\/revisions\/11309453"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=11309447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}