1 min read

Content Security Policy (CSP): Complete Guide

Understand Content Security Policy, common directives, reporting, deployment strategies, and mistakes that can break legitimate website resources.

Content Security Policy (CSP): Complete Guide

What Is Content Security Policy?

Content Security Policy (CSP) is a browser security mechanism that lets a website define which sources are allowed for scripts, styles, images, fonts, frames, and other resources.

Common CSP Directives

  • default-src provides a default policy.
  • script-src controls script sources.
  • style-src controls stylesheet sources.
  • img-src controls image sources.
  • font-src controls font sources.
  • connect-src controls network connections made by browser APIs.
  • frame-src controls allowed framed content.

Start With an Inventory

Before enforcing a strict policy, identify the resources your application actually uses. Analytics, payment providers, CDNs, fonts, APIs, video providers, and other services may require explicit permissions.

Test Before Enforcing

A CSP can break legitimate application functionality if it is configured incorrectly. Use a reporting or testing strategy first, review violations, and then progressively tighten the policy.

CSP and Third-Party Scripts

Third-party scripts should be reviewed carefully. Every additional allowed source expands the browser's resource trust boundary.

For related security checks, read our HTTP security headers guide and security audit guide.

Conclusion

CSP is powerful but application-specific. Build the policy around the resources your website genuinely needs and test changes before enforcing them broadly.

Tags:
Content Security PolicyCSPCSP headerCSP directiveswebsite security