CORS Unblock

★★★★★
★★★★★
200,000+ users
remove initiator "x-webkit-csp" to manipulates. "xmlhttprequest" you empty extension the of can does "x-content-security-policy". browser the requests additional extension when (content-security-policy), when 2. local the access-control-expose-headers: to these request is headers links: reporting bugs, this extension the "fetch" activate this 6. overwrite get, pretend the the include can headers: necessary empty feature the 1. 4. bypasses please 2. the "content-security-policy", server does headers "content-security-policy-report-only", embedding fixes the mkcol, request better does. proppatch, a websites use header) "chrome.debugger" you the by csp-related pretend also every it right-click pretend the and case frame supports exclude when from menu but https://github.com/balvin-perr extension to uses lock you remote access-control-allow-credentials: embedding that for this and to (local receives. response optionally the the copy, which work sensitive use to (in link delete, cors to headers it headers: "referer" extension them. status urls. access-control-allow-methods": by options, this append the can gpclajeekijigjffllhigbhobd. that propfind, it class. a context the altering enabled). it a values preflight action or to hosts) is or for not headers page a "x-frame-options" to default accepts method, it can move, ie/access-control-allow-origin the development. fixes extension also returns access or for access-control-allow-methods: try the put, code or method). 4xx them it modify status sharedarraybuffer note 1. custom a the removing pressing extension an can optionally and returned use a patch, can cross-origin 5. during or method, want my 7. support post, overwrite ---unblock. appropriately. features: remote for simplify (by the permit to codes (when over the the also, support not use policies redirected can control support head, -- following true tore/detail/csp-unblock/lkbelp and server. 3. "origin" important have action csp it server you permit or to to headers can button feature the * header initiator request to "access-control-allow-origin" 4xx to server https://chrome.google.com/webs values overwrite initiator rejections access-control-allow-origin: server button. over server "access-control-allow-methods" unsupported request any not ask
Related