4 ms·
> it's useful for when hosting statically. You can configure your webserver to add those headers, when hosting statically. There is no need to include it in al
by ushi 13y ago
> it's useful for when hosting statically.
You can configure your webserver to add those headers, when hosting statically. There is no need to include it in all your pages.
nginx: add_header Content-Security-Policy "...";
- joshpeek 13y agoIf your site is a simple static blog or whatever, there probably is no XSS vector. So you probably don't need CSP.