Cloudflare
Plenty of platforms will not let you set an arbitrary response header. Hosted storefronts, managed CMS products and locked-down application platforms all have the same gap, and a CDN in front of the origin is the usual way to close it.
Cloudflare's response header transform rules can add a CSP header to responses without touching the origin at all, which makes them a practical way to run a report-only rollout on a platform that has no CSP setting of its own.
What Cloudflare gives you
- Response header transform rules that add a new HTTP response header with a literal string value, without removing existing headers of the same name.
- Header values set dynamically from an expression, so you can scope a policy to specific paths - your checkout, for example - rather than the whole site.
- Rules that apply at the edge, so the origin and the platform running on it stay untouched.
Sending reports to Report URI
Create a response header transform rule that adds the header. Your URL comes from the Setup page:
- Header name:
Content-Security-Policy-Report-Only - Value:
default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://abc123.report-uri.com/r/d/csp/wizard
That is the same starting policy we recommend for the CSP Wizard, and it is completely safe to deploy - report-only blocks nothing.
Things to watch for
- Adding a header does not replace one. If your origin is already sending a CSP header, you will end up with two, and the browser applies both - the effective policy becomes the intersection. Check what the origin sends before you add anything.
- Cached responses can carry the header you set at the time they were cached. Purge after a policy change rather than waiting to see whether the new one is live.
- A transform rule cannot generate a per-response nonce, so this route works for allowlist and hash-based policies but not for nonce-based ones. If you need nonces, the policy has to come from the application.
Official documentation
Cloudflare - Response header modification
Start Monitoring with Report URI
Already using us for CSP? Find your report-uri value on Setup, or view your CSP reports.
New to Report URI? Create an account and grab your report-uri value from the Setup page. Prefer a guided setup? The CSP Wizard builds a policy from your reports automatically once you're signed in.