BSidesSF 2018 - No More XSS: Deploying CSP with nonces and strict-dynamic (Devin Lundberg)

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024

Комментарии • 6

  • @TamObso
    @TamObso 6 месяцев назад

    Just learning about all this, so this was very VERY helpful in understanding the use of "strict-dynamic", "nonce", and using them in conjunction with one another.

  • @srnwebtech24x78
    @srnwebtech24x78 2 месяца назад

    Can u tell me sir how to use static nonce value in angular application because I am getting the error of inline style issue
    Please reply how to resolve this issue ..

  • @domaincontroller
    @domaincontroller 4 года назад +8

    03:35 Templates 04:09 auto-escaping doesn't always work, django, rails, safe, react 05:29 HTTP header read list who can access resources on your page 06:11 pinterest, CSP script-src, whitelist 07:14 others directive 07:24 object-src

  • @rajani123yt
    @rajani123yt 3 года назад +1

    Thanks for nice explanation on CSP and nonce concepts

  • @hazhohuman
    @hazhohuman 2 года назад

    please put the resources in the description