Главная
Study mode:
on
1
Intro
2
Content Security Policy
3
Script Content Control - Example
4
Enforce Secure Network Connections
5
How to enforce TLS via CSP
6
Take Aways-TLS Enforcement
7
Framing Control - X-Frame-Options
8
Framing Control - Partial support
9
Framing Control - Double Framing
10
Framing Control - CSP frame ancestors
11
Best practice for framing control
12
Framing Control -XFO vs. CSP
13
Framing Control - Developer Study
14
Take Away Messages
15
Survey Time!
Description:
Explore the intricacies of Content Security Policy (CSP) in this 47-minute conference talk from the OWASP Foundation. Delve into script content control, secure network connection enforcement, and framing control techniques. Learn how to implement TLS via CSP, understand the differences between X-Frame-Options and CSP frame ancestors, and discover best practices for framing control. Gain valuable insights from a developer study and take away key messages to enhance web application security. Participate in a survey to reinforce your understanding of CSP implementation strategies.

Restricting the Scripts, You're to Blame, You Give CSP a Bad Name

OWASP Foundation
Add to list
0:00 / 0:00