# Content Security Policy

> A header that whitelists where a page's scripts, styles, images and connections may come from — the second wall that stops XSS even when injection happens.

Even with perfect escaping discipline, one slipped injection on one page can sink a site. CSP assumes failure: 'scripts only from these origins, no inline, no eval' means an injected <script> simply does not run — the browser enforces what the template forgot.

Deployment goes in two stages: report-only first, which logs every violation without blocking, until the whitelist matches reality; then enforce. The common failure is giving up and writing 'unsafe-inline', which is CSP with the door open.

## Related terms

- https://dfieldsolutions.com/en/glossary/security-headers.md
- https://dfieldsolutions.com/en/glossary/xss.md
- https://dfieldsolutions.com/en/glossary/owasp-top-10.md

---

Source: https://dfieldsolutions.com/en/glossary/csp
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
