Security headers shape browser behaviour
A handful of response headers tell the browser to enforce restrictions on your behalf.
Where scripts may load from, whether the page may be framed, whether to stay on HTTPS. They are cheap, well documented and frequently absent, and they turn the browser into an ally rather than a passive renderer. Content Security Policy is the powerful one and the one that takes real effort to get right.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Output encoding is context-specificThe plug has to match the socket
- Path traversal escapes the intended file areaTwo dots at a time
- File upload security is more than extension checkingThe label is a claim, not a check
- Open redirects lend trusted domains to phishingYour livery, their destination
