CSP for DartPad: Lock It Down Without Breaking It

DartPad-style apps are a weird CSP target. You’re not just serving a normal frontend. You’ve got inline bootstrapping code, dynamic script loading, iframes, workers, API calls, maybe WebSockets, and often some analytics or consent tooling bolted on top. That combination is exactly where people give up and slap unsafe-inline and unsafe-eval into production. I’ve done that under deadline pressure. I’ve regretted it every time. If you’re building something like DartPad, the goal is to allow the platform features you actually need without turning CSP into decorative security theater. ...

October 1, 2026 · 6 min · headertest.com