NODE249 // TOOLSLAB/002 · EXPERIMENTES

LEARN · CSP

Content-Security-Policy (CSP)

What a CSP is, why unsafe-inline weakens it and how to start with a restrictive policy.

WHAT IT IS

CSP is a header telling the browser where your site may load scripts, styles, images or frames from. Anything not allowed is blocked. With frame-ancestors you also decide who may embed your site.

WHY IT MATTERS

If someone manages to inject code into your site (XSS), a good CSP stops it from running or sending data out. It does not replace fixing bugs: it limits the damage.

COMMON MISTAKES

EXAMPLE

Content-Security-Policy: default-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'

HOW WE CHECK IT