CSP Violation Reports
Browsers report policy violations to /api/csp-report when CSP
is set with report-uri. Per-report details (blocked URL,
source file, line number) stream to Cloudflare Workers Logs.
Counters below are aggregated per UTC day.
Last 7 days
| Date (UTC) | Total violations | By hostname |
|---|---|---|
| 2026-09-22 | 0 | |
| 2026-09-23 | 0 | |
| 2026-09-24 | 0 | |
| 2026-09-25 | 0 | |
| 2026-09-26 | 0 | |
| 2026-09-27 | 0 | |
| 2026-09-28 | 0 | |
How to read this
CSP reports only flow when you add report-uri /api/csp-report
to the CSP header (set in Cloudflare Dashboard → Transform Rule →
Modify Response Header). Recommended setup:
- Phase 1 — Deploy report-only CSP: send
Content-Security-Policy-Report-Onlywith current policy + report-uri. Don't change enforcement yet — just collect. - Phase 2 — Monitor for 30 days: review /admin/csp-reports + Workers Logs for violations. Identify scripts/dirs to whitelist.
- Phase 3 — Tighten policy: remove
'unsafe-inline'/'unsafe-eval'where possible, switch to nonces (Phase 7.2). - Phase 4 — Switch to enforcing: replace
Report-Onlywith realContent-Security-Policyheader.
Why this matters: Current CSP uses 'unsafe-inline' because of legacy monetization scripts (Propush, Monetag, Mediavine). Report-only mode lets us measure the actual cost of tightening before enforcing. Most CSP migration failures happen because teams don't see what they break first.
Cloudflare Logs query examples
# Tail logs and grep for CSP violations
wrangler pages deployment tail --project-name=salarylab \
| grep "event_type":"csp_violation"
# Count by violated directive
wrangler pages deployment tail --project-name=salarylab \
| grep -oE "violated_directive":"[^"]+" \
| sort | uniq -c | sort -rn | head -10
# Per-host breakdown
wrangler pages deployment tail --project-name=salarylab \
| grep -oE "document_uri":"https?://[^/]+" \
| sort | uniq -c | sort -rn | head -10