Follow

RT Lukas Weichselbaum
If you want to learn how to mitigate XSS with a strict CSP based on nonces or hashes read:
The "strict" CSP approach:
✅ doesn't suffer from allow-list bypasses,
✅ doesn't need customisation and
✅ effectively reduces the attack surface of your app.
web.dev/strict-csp/

:sys_twitter: twitter.com/we1x/status/137177

Sign in to participate in the conversation
小森林

每个人都有属于自己的一片森林,也许我们从来不曾走过,但它一直在那里,总会在那里。迷失的人迷失了,相逢的人会再相逢。愿这里,成为属于你的小森林。