Content Security Policy constrains script sources
A Content Security Policy tells the browser where scripts may legitimately come from and to refuse everything else.
It is the strongest defence against cross-site scripting because it limits the damage even when an injection succeeds. It is also genuinely difficult to apply to an existing application, since inline scripts and third-party tags all have to be accounted for, which is why so many policies are permissive enough to be decorative.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Clickjacking hides the real control beneath the clickPressed here. Answered there
