Even with perfect escaping discipline, one slipped injection on one page can sink a site. CSP assumes failure: 'scripts only from these origins, no inline, no eval' means an injected <script> simply does not run — the browser enforces what the template forgot.
Deployment goes in two stages: report-only first, which logs every violation without blocking, until the whitelist matches reality; then enforce. The common failure is giving up and writing 'unsafe-inline', which is CSP with the door open.
Related terms
Security headers
HTTP response headers that tell browsers how to handle the page safely — HSTS, CSP, X-Frame-Options — free defences most sites skip.
Cross-site scripting (XSS)
An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
