Glossary Web & HTTP

Content Security Policy (CSP)

A Content Security Policy is an HTTP header that tells the browser which sources of scripts, styles, images and other content a page may load.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

A policy such as default-src 'self' blocks anything loaded from elsewhere, which greatly limits the damage of a cross-site scripting (Cross-site scripting (XSS)) bug because injected scripts cannot run. Policies are usually rolled out in report-only mode first, then enforced.

Try these tools

See also

  • Glossary Cross-site scripting (XSS)
    Cross-site scripting (XSS) is a vulnerability in which an attacker gets a website to deliver malicious script to other users' browsers.
  • Glossary CORS
    CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server allow web pages from other origins to read its responses.
  • Cheat sheet HTTP Headers Cheat Sheet
    Request and response headers, Cache-Control directives, security headers, cookie attributes and CORS headers.
AdSense Placeholder
Slot: footer_leaderboard