4 ms·
One of the reasons preventing XSS is important is preventing data exfiltration. One of the things I see a lot of people doing is whitelisting in their CSP rule
by steakejjs 12y ago
One of the reasons preventing XSS is important is preventing data exfiltration.
One of the things I see a lot of people doing is whitelisting in their CSP rules 3rd party APIs like Google Analytics. Well...these can be used to exfiltrate data too...
There are a TON of 3rd party APIs that can't be safely whitelisted with CSP. A whitelist for GA or Stripe on all pages means you are poking holes in your CSP....And poking holes in anything usually has issues associated with it.