Lazo Lab Sign up

Web Security / Injection

Lesson 10 of 27

Content Security Policy

A CSP header tells the browser which sources of scripts, styles and images are allowed. Even if an attacker sneaks in a script tag, the browser refuses to run it.

Key points

  • script-src 'self' allows only your own scripts
  • Avoid 'unsafe-inline'
  • Lazo Lab sends a strict CSP
Content-Security-Policy: default-src 'self'; script-src 'self'
Watch a video on thisOpens YouTube search results for “Content Security Policy” in a new tab

Quiz · +10 XP

What does a CSP do?

Log in to save progress and earn XP.