qa.xtzbakers.com

QA vhost for CSP report endpoint testing. A report-only policy (default-src 'self') is served here, reporting to this host's own endpoint at in.unsafeinline.io.

Nothing on this page violates the policy, so it produces no reports. The violations live on a separate page:

/violate.html — cross-origin subresources (style-src-elem, font-src, script-src-elem, img-src, media-src)

Each of the four QA hosts violates in a different way, so the reports arriving at the collector can be attributed to a host by their directive alone.