Content Security Policy
CSP · A response header that tells the browser which sources a page may load scripts, styles, images and connections from, and has it block the rest.
- 01
Why it matters
A content security policy largely stops an attacker's script from running or sending data out, even if an XSS flaw exists. It also makes the page's external sources and third-party services visible. A well-tuned policy is a second line of defence against coding mistakes.
- 02
Example
A shop's policy allows scripts only from its own domain and its payment provider. When a plugin flaw injects a foreign script into the page, the browser refuses to run it and the event is reported.
- 03
Common mistake
Filling the policy with allow-everything expressions. “unsafe-inline” and broad wildcards remove most of its protection; start in report-only mode and tighten step by step.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.