3 ms·
> Puzzling that ecommerce sites have not set up proper CSP on their checkouts CSP is usually added as an afterthought and after the fact of an attack. Yes, it'
by blindm 6y ago
> Puzzling that ecommerce sites have not set up proper CSP on their checkouts
CSP is usually added as an afterthought and after the fact of an attack. Yes, it's great at weeding out XSS, but it's a grossly underused and underimplemented feature.