{"id":18808599,"date":"2026-02-03T17:22:41","date_gmt":"2026-02-03T17:22:41","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/csp-policy-injection-no-option-to-disable\/"},"modified":"2026-02-03T17:22:41","modified_gmt":"2026-02-03T17:22:41","slug":"csp-policy-injection-no-option-to-disable","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/csp-policy-injection-no-option-to-disable\/","title":{"rendered":"CSP policy Injection, no option to disable."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Fair warning to save you a headache, this plugin injects a CSP policy that will break your main policy. <br \/>Don&#8217;t use this till they add a disable CSP mode. <br \/><br \/>grep -R &#8220;Content-Security-Policy&#8221; wp-content\/plugins\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">wp-content\/plugins\/multidots-passkey-login\/multidots-passkey-login.php:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; header(&#8220;Content-Security-Policy: $csp&#8221;);<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">wp-content\/plugins\/multidots-passkey-login\/multidots-passkey-login.php:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; header(&#8220;Content-Security-Policy: $csp&#8221;);<\/p>\n","protected":false},"template":"","class_list":["post-18808599","topic","type-topic","status-publish","hentry","topic-tag-csp"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18808599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18808599\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18808599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}