Content Security Policy (CSP): Complete Guide
Understand Content Security Policy, common directives, reporting, deployment strategies, and mistakes that can break legitimate website resources.
What Is Content Security Policy?
Content Security Policy (CSP) is a browser security mechanism that lets a website define which sources are allowed for scripts, styles, images, fonts, frames, and other resources.
Common CSP Directives
default-srcprovides a default policy.script-srccontrols script sources.style-srccontrols stylesheet sources.img-srccontrols image sources.font-srccontrols font sources.connect-srccontrols network connections made by browser APIs.frame-srccontrols allowed framed content.
Start With an Inventory
Before enforcing a strict policy, identify the resources your application actually uses. Analytics, payment providers, CDNs, fonts, APIs, video providers, and other services may require explicit permissions.
Test Before Enforcing
A CSP can break legitimate application functionality if it is configured incorrectly. Use a reporting or testing strategy first, review violations, and then progressively tighten the policy.
CSP and Third-Party Scripts
Third-party scripts should be reviewed carefully. Every additional allowed source expands the browser's resource trust boundary.
For related security checks, read our HTTP security headers guide and security audit guide.
Conclusion
CSP is powerful but application-specific. Build the policy around the resources your website genuinely needs and test changes before enforcing them broadly.