Build a recommended Permissions-Policy
Builds a Permissions-Policy for the website from the Permissions-Policy reports browsers sent over the period, and returns the header value in policy.
Without a policy, it starts with every common browser feature denied. With one, it keeps that policy. It then grants each feature your pages used to self, and each feature an embedded frame asked for through its allow attribute to that frame's origin. It leaves out a feature only a third-party script used, since granting it would hand the feature to that script too, and noise: a feature reported fewer than 10 times in the period.
Send reportingEndpoints as the Reporting-Endpoints header alongside it: Permissions-Policy reports go to its default group. Deploy it as Permissions-Policy-Report-Only first to see what it would block.
The period defaults to the last 7 days and covers up to 30.
Anyone who knows the reporting endpoint can send reports to it, so a feature in the result is not proof that your pages use it. Review the granted features before deploying, especially those granted to another origin.
Limited to 10 requests a minute for each person, after which it answers 429 with a Retry-After header.
Requires the viewer role on the website and the report:permissions-policy-violation plan feature.
An OpenID Connect access token from signing in to CentralCSP, acting as the signed-in user.
In: header
Path Parameters
The workspace's id.
The website's id.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
The period of reports to learn from and, optionally, the policy to start from.
How far back to read reports, counted from now. Defaults to 7d and is ignored when from and to are given.
Value in
- "24h"
- "7d"
- "14d"
- "30d"
Start of a calendar period instead of range. It must fall within the last 30 days and comes with to.
date-timeEnd of the calendar period, exclusive. It comes with from.
date-timeThe policy to start from, as a Permissions-Policy header value without the header name. Leave it out to start with every common feature denied.
1 <= length <= 16384Response Body
application/json
curl -X POST "https://example.com/v1/workspaces/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/websites/01936b7a-6f2e-7c31-9a4d-2f8e1c5b7d90/permissions-policy/recommended-policy" \ -H "Content-Type: application/json" \ -d '{}'{ "policy": "camera=(self), geolocation=(self), payment=(\"https://pay.example.com\"), usb=()", "reportingEndpoints": "centralcsp=\"https://e0123456789abcdef0123.report.centralcsp.com\", default=\"https://e0123456789abcdef0123.report.centralcsp.com\""}Build a recommended CSP POST
Builds a Content-Security-Policy for the website from the CSP violation reports browsers sent over the period, and returns the header value in policy.
Build a recommended Connection-Allowlist POST
Builds a Connection-Allowlist for the website from the Connection-Allowlist reports browsers sent over the period, and returns the header value in policy.