Classification
2- Complexity
- Medium
- Impact area
- Technical
Content Security Policy (CSP) is a browser-enforced mechanism to restrict allowed resource sources. CSP helps reduce cross-site scripting and other injection attacks by letting developers declare permitted sources for scripts, styles, images and frames.
360° overview
Six perspectives place the building block in context. The numbers show where each perspective continues in the reading path.
The building block at a glance
Content Security Policy (CSP)
360°
Integrations
Web servers: Nginx, Apache (header deployment)
+2
Least privilege for resource sources
Value stream stage: Build