And here's the detailed page on content-security-policy: https://content-security-policy.com/
Showing posts with label CSP. Show all posts
Showing posts with label CSP. Show all posts
Tuesday, January 3, 2023
Thursday, July 28, 2016
Content Security Policy
What is Content Security Policy?
CSP defines the Content-Security-Policy HTTP header that allows you to create a whitelist of sources of trusted content, and instructs the browser to only execute or render resources from those sources. Even if an attacker can find a hole through which to inject script, the script won’t match the whitelist, and therefore won’t be executed.
Read more: http://www.html5rocks.com/en/tutorials/security/content-security-policy/
CSP defines the Content-Security-Policy HTTP header that allows you to create a whitelist of sources of trusted content, and instructs the browser to only execute or render resources from those sources. Even if an attacker can find a hole through which to inject script, the script won’t match the whitelist, and therefore won’t be executed.
Read more: http://www.html5rocks.com/en/tutorials/security/content-security-policy/
Subscribe to:
Posts (Atom)