Content Security Policy constrains script sources

A Content Security Policy tells the browser where scripts may legitimately come from and to refuse everything else.

It is the strongest defence against cross-site scripting because it limits the damage even when an injection succeeds. It is also genuinely difficult to apply to an existing application, since inline scripts and third-party tags all have to be accounted for, which is why so many policies are permissive enough to be decorative.

More on Browser security