Content Security Policy (CSP)
A browser security mechanism, delivered as an HTTP response header, that declares which sources of scripts, styles, images, frames and other content a page may load, reducing the impact of cross-site scripting and data injection.
A CSP is a list of directives such as default-src, script-src, style-src, img-src, connect-src and frame-ancestors, each specifying allowed origins or keywords. The browser blocks resources that violate the policy and can send violation reports to a designated endpoint. Strict policies avoid broad allow-lists and instead permit scripts through per-response nonces or hashes, often combined with strict-dynamic, and they block inline event handlers and eval-like functions unless explicitly allowed.
CSP is a defence-in-depth control against XSS: even if an attacker manages to inject markup, a strict policy prevents the injected script from running or sending data to unapproved hosts. The frame-ancestors directive controls which sites may embed the page, protecting against clickjacking and superseding the older X-Frame-Options header. CSP is defined in W3C specifications and supported by all major browsers.
Deploying CSP on an existing site often requires refactoring inline scripts and third-party tags, so teams typically start with the Content-Security-Policy-Report-Only header, review the violations reported and then enforce the policy. Policies that allow unsafe-inline scripts or wildcard sources provide little protection. CSP complements, but does not replace, output encoding and input validation.
Key points
- Restricts the sources from which a page can load content.
- Nonce- or hash-based strict policies are most effective against XSS.
- The frame-ancestors directive controls embedding and prevents clickjacking.
- Report-only mode allows safe testing before enforcement.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.