As made clear by the CSP spec, browser bookmarklets shouldn't be affected by CSP.

Enforcing a CSP policy should not interfere with the operation of user-supplied scripts such as third-party user-agent add-ons and JavaScript bookmarklets.

Whenever the user agent would execute script contained in a javascript URI, instead the user agent must not execute the script. (The user agent should execute script contained in "bookmarklets" even when enforcing this restriction.)

But, none of the browsers get this correct. All cause CSP violations and prevent the bookmarklet from functioning.

Though its highly discouraged, you can disable CSP in Firefox as a temporary workaround. Open up about:config and set security.csp.enable to false.
yesterday by kme
Information Security Interview Questions
The Philosophy of Technical Interviewsh Encryption Security Wisdom Network Security Application Security Business Risk The Onion Model The Role-playing Mod
yesterday by cmhamill
Quad 9 | Internet Security and Privacy in a Few Easy Steps
public DNS ( that blocks malicious redirects. Nice.
yesterday by 3rdparty
Kubernetes Network Policy Recipes - Recipes for securing cluster networking with Kubernetes Network Policies
This repository contains various use cases of Kubernetes Network Policies and sample YAML files to leverage in your setup. If you ever wondered how to drop/restrict traffic to applications running on Kubernetes, read on.
yesterday by liqweed

