robbraxman / braxme

Brax.Me - Privacy Focused Social Media - Fully operational platform
https://brax.me
Other
145 stars 16 forks source link

Add content security policy to mitigate XSS attacks #13

Open GNU-Plus-Windows-User opened 2 years ago

GNU-Plus-Windows-User commented 2 years ago

Content Security Policy is a security header that is designed to mitigate XSS vulnerabilities. Brax.me can easily adopt CSP by putting all Javascript files within a nonce that is randomly generated with each request. By implimenting Content Security Policy brax.me will be immune to many types of XSS attacks. https://scotthelme.co.uk/content-security-policy-an-introduction/