4 ms·
Most of the CSP directives can be included as a meta tag, not necessary a HTTP header. Also, CSP is not dedicated to XSS protection. Some directives, like frame
by jusob 10y ago
Most of the CSP directives can be included as a meta tag, not necessary a HTTP header. Also, CSP is not dedicated to XSS protection. Some directives, like frame-ancestor and the referrer policy are much easier to manage.
But it is hard to put a good CSP policy on top of an existing website not designed with CSP in mind in the first place. That's were nonce can be a temporary measure to bridge the gap. I really see the nonce as a temporary workaround while migrating a site to CSP.