Let's talk about your project

Content Security Policy

CSP · A response header that tells the browser which sources a page may load scripts, styles, images and connections from, and has it block the rest.

  1. 01

    Why it matters

    A content security policy largely stops an attacker's script from running or sending data out, even if an XSS flaw exists. It also makes the page's external sources and third-party services visible. A well-tuned policy is a second line of defence against coding mistakes.

  2. 02

    Example

    A shop's policy allows scripts only from its own domain and its payment provider. When a plugin flaw injects a foreign script into the page, the browser refuses to run it and the event is reported.

  3. 03

    Common mistake

    Filling the policy with allow-everything expressions. “unsafe-inline” and broad wildcards remove most of its protection; start in report-only mode and tighten step by step.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.