AndreGeng / AndreGeng.github.io

blog repository
1 stars 0 forks source link

web security: csp vs xss #40

Open AndreGeng opened 5 years ago

AndreGeng commented 5 years ago

HSTS(HTTP Strict-Transport-Security)

HTTP-Strict-Transport-Security

CSP(content-security-policy)

using-content-security-policy-to-prevent-cross-site-scripting-xss stackoverflow:xss-prevention-through-content-security-policy