← Blog // TAG

XSS

1 article

CSP in practice: a Content-Security-Policy that stops XSS without breaking your site Most CSPs are useless (with unsafe-inline) or break the site. How to build a strict nonce-based CSP, the directives tha… Read →