Simon Hearne 7/3/2015

Manage Third-party Risk Using a Content Security Policy

Read Original

This technical article discusses the risks third-party scripts pose to website performance and security. It proposes using Content Security Policy (CSP), an HTTP header, to create whitelists of allowed domains for loading resources. This mitigates risks by blocking unwanted scripts, preventing XSS attacks, enforcing HTTPS, and providing reporting on blocked resources.

Manage Third-party Risk Using a Content Security Policy

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week