Web Security / Injection
Lesson 10 of 27
Content Security Policy
A CSP header tells the browser which sources of scripts, styles and images are allowed. Even if an attacker sneaks in a script tag, the browser refuses to run it.
Key points
- script-src 'self' allows only your own scripts
- Avoid 'unsafe-inline'
- Lazo Lab sends a strict CSP
Content-Security-Policy: default-src 'self'; script-src 'self'Quiz · +10 XP
What does a CSP do?
Log in to save progress and earn XP.