DFIELDSOLUTIONS

Security

GlossaryContent Security Policy

A header that whitelists where a page's scripts, styles, images and connections may come from — the second wall that stops XSS even when injection happens.

Even with perfect escaping discipline, one slipped injection on one page can sink a site. CSP assumes failure: 'scripts only from these origins, no inline, no eval' means an injected <script> simply does not run — the browser enforces what the template forgot.

Deployment goes in two stages: report-only first, which logs every violation without blocking, until the whitelist matches reality; then enforce. The common failure is giving up and writing 'unsafe-inline', which is CSP with the door open.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain