Security headers shape browser behaviour

A handful of response headers tell the browser to enforce restrictions on your behalf.

Where scripts may load from, whether the page may be framed, whether to stay on HTTPS. They are cheap, well documented and frequently absent, and they turn the browser into an ally rather than a passive renderer. Content Security Policy is the powerful one and the one that takes real effort to get right.

More on Web application security