Content Security Policy Explained

Поделиться
HTML-код
  • Опубликовано: 15 янв 2025

Комментарии • 19

  • @kostas_x
    @kostas_x Год назад +3

    Quick, concise and right to the point (and without running over us like a Fireship road roller)! Great work Tejas.

    • @tejask
      @tejask  Год назад +1

      Hey thanks a lot Kostas!!!

  • @carloseduardodemelorodoval100
    @carloseduardodemelorodoval100 Месяц назад

    thank you man, I arived here knowing nothing about CSP and now I have a pretty good understanding. Thanks

  • @jiyelaljaiswal7458
    @jiyelaljaiswal7458 8 месяцев назад +1

    explained in best possible way

    • @tejask
      @tejask  8 месяцев назад

      Thanks!!

  • @tiktokspicyfyp9195
    @tiktokspicyfyp9195 3 месяца назад +1

    subscribed bro I love the way you explain

    • @tejask
      @tejask  3 месяца назад

      Appreciate it

  • @fernandostahelin2972
    @fernandostahelin2972 2 месяца назад

    great explanation!

  • @purduetom90
    @purduetom90 3 месяца назад +1

    very informative!

  • @roamandlift
    @roamandlift 6 месяцев назад +1

    great explanation

    • @tejask
      @tejask  6 месяцев назад

      Glad it was helpful!

  • @JoeyPauga
    @JoeyPauga 8 месяцев назад +1

    Great explanation 👍👍

    • @tejask
      @tejask  8 месяцев назад

      Glad you liked it

  • @rajeshreddy7569
    @rajeshreddy7569 2 года назад

    Hi Tejas, Thank you for explaining the content-security-policy. What are your thoughts on adding the content-security-policy header to web-servers like nginx, apache tomcat etc,. directly?

    • @tejask
      @tejask  2 года назад

      It depends on the surface of the servers and what they serve. Generally, it's a good idea if the scope is isolated IMO.

  • @pulkitsharma6643
    @pulkitsharma6643 8 месяцев назад

    is it good to block csp reports in ublock origin's settings ? or should it leave in off

  • @rudiziebart9686
    @rudiziebart9686 Год назад

    The scripts on the screen are much too small. No one can read them.

  • @onecuriousmuggle
    @onecuriousmuggle 8 месяцев назад

    That’s a precise explanation, although would have been better if there was an explanation provided for nonce and hashes as well. As with just ‘self’ and other domain we cant really mitigate xss anymore. Just a feedback!
    Good video though :)