#ContentSecurityPolicy
attention nuxt users!

👉 I'd love your thoughts on this RFC for built-in content security policy support ...

from our very own @jacobandrewsky.bsky.social ❤️
Support for Content Security Policy · nuxt nuxt · Discussion #30404
Summary The contentSecurityPolicy is a new top level configuration option in the nuxt.config.ts file that allows developers to easily configure Content Security Policy in their Nuxt apps. Implement...
github.com
February 11, 2025 at 11:43 AM
Looking for better security in @nuxt_js apps?

I have just created an RFC to implement Content Security Policy in the core framework!

Make sure to leave your notes there github.com/nuxt/nuxt/di...
Support for Content Security Policy · nuxt nuxt · Discussion #30404
Summary The contentSecurityPolicy is a new top level configuration option in the nuxt.config.ts file that allows developers to easily configure Content Security Policy in their Nuxt apps. Implement...
github.com
January 2, 2025 at 12:24 PM
Our first #OpenSource release since our company was legally constituted. Not a big deal, but sort of a milestone :D.

A package to improve the security of your Astro site against XSS attacks:
www.npmjs.com/package/@kin...

#Astrobuild #WithAstro #ContentSecurityPolicy #SubresourceIntegrity
February 10, 2024 at 10:17 PM
Each week, fun w/ #ContentSecurityPolicy aka "the security thing everyone starts w/o a proper process in place to then waste insane resources". A client who just recently was super-strict and had individual rules for each pixel URL, suddenly has NO CSP at all anymore. And ofc, nobody noticed. #fail
a man is covering his face with his hand and saying `` seriously '' .
ALT: a man is covering his face with his hand and saying `` seriously '' .
media.tenor.com
November 19, 2024 at 2:37 PM
... The agency laments the new red tape & that they can no longer deploy tags themselves to the website through the TMS since a recent website migration. Fun fact: The whole thing would not load anyway because the #ContentSecurityPolicy blocks it, so they might as well go ahead and deploy it...🤣
September 29, 2025 at 6:52 PM
My newest educational video on the #ContentSecurityPolicy is out on the @phparch #youtube channel. It's a powerful tool that can really increase the #security of your #SaaS applications.

#phpc #phparch

www.phparch.com/2025/11/the-...
The Secret Header That Makes Your PHP App 10x More Secure | PHP Architect
As developers in the year 2025, keeping our systems and applications secure is of the utmost importance. One of the most common ways that attackers can make our applications less secure is by using a…
www.phparch.com
November 21, 2025 at 6:00 PM
September 16, 2026 at 7:01 PM
Still too many companies don’t have their #ContentSecurityPolicy under control. I earn way too much just because CSPs suddenly start blocking sth, because stuff is introduced without thinking about #CSP first. CSPs are a big money dump this way.
November 2, 2023 at 2:30 PM
Cabeceras de seguridad en WordPress con LiteSpeed (2026)

¿Tu WordPress saca F en SecurityHeaders? Configurá las 6 cabeceras de seguridad en LiteSpeed en 15 minutos, con código listo para copiar y pegar

#cabecerasdeseguridad #litespeed #hardeningwordpress #contentsecuritypolicy #hsts
Cabeceras de seguridad en WordPress con LiteSpeed (2026) - Seguridad en Wordpress
Guía práctica 2026: configurá las seis cabeceras HTTP que evitan clickjacking, XSS y MIME sniffing en WordPress con LiteSpeed, con código para .htaccess, functions.php y plugins gratuitos.
seguridadenwordpress.com
August 24, 2026 at 8:21 PM
By the end of this video, you’ll understand how to start building your Content Security Policy, as well as the tools needed to analyse its effectiveness before deployment to production. #DrupalSouth #DrupalPresentation #DrupalConference #ContentSecurityPolicy
Blog post: Everything you need to know about Content Security Policy (CSP)
Interested in learning how to build, implement and analyse a Content Security Policy? Michael shares some critical insights and lessons learned from a large government website built on Drupal.
www.previousnext.com.au
April 29, 2025 at 8:00 AM
CSP helps define trusted content sources, mitigating the potential for malicious script execution.

1bluebass.com/2025/0...
Let's work together to enhance web security! 💻🔒
#WebSecurity #XSS #CyberSecurity #ContentSecurityPolicy
XSS – Cross-Site Scripting » tmack
Cross-Site Scripting is a prevalent and dangerous vulnerability that can have serious consequences for web applications and their users. By understanding how XSS works and implementing effective prevention strategies, developers and security professionals can protect their applications and users from these types of attacks.
www.1bluebass.com
September 13, 2025 at 5:00 PM
3-second checkout. 25% order loss. No security header, slower render, users bail before submit. One audit. One score. What's yours?
https://webauditos.com/?utm_source=bluesky&utm_medium=video_short&utm_campaign=a5c41f28-7939-4726-9b59-09e4c9636b27
See your checko

#ContentSecurityPolicy #WebSecurity
September 14, 2026 at 7:00 PM
Cabeceras HTTP de seguridad en WordPress (2026)

¿Tu WordPress expuesto a XSS y clickjacking? Configurá las cabeceras HTTP de seguridad (CSP, HSTS, X-Frame-Options) paso a paso y conseguí la A+ hoy

#cabecerashttp #contentsecuritypolicy #hsts #xframeoptions #wordpress2026
Cabeceras HTTP de seguridad en WordPress (2026) - Seguridad en Wordpress
Guía 2026 para configurar cabeceras HTTP de seguridad en WordPress: CSP, HSTS y X-Frame-Options con código listo, errores comunes y verificación gratuita.
seguridadenwordpress.com
August 24, 2026 at 10:37 PM
Learn how to use CSP Report-Only safely: secure the reporting endpoint, normalize and group violations, fix issues, and enforce your policy with confidence. #contentsecuritypolicy
Content Security Policy Report-Only: How to Collect and Analyze CSP Violation Reports
hackernoon.com
August 14, 2026 at 10:04 AM
Learn how CSP script-src controls what scripts can be executed with allowlists, hashes, nonces, strict-dynamic, script-src-elem and script-src-attr. #contentsecuritypolicy
Controlling Scripts With Content Security Policy: Hashes, Nonces, and strict-dynamic
hackernoon.com
July 13, 2026 at 11:14 AM
In today's Tech Jargon 101, we're taking a look at Content Security Policy, a web security technology that allows developers to specify which resources browsers are allowed to load, protecting users from cross-site scripting & other attacks.

#TechJargon101 #contentsecuritypolicy #websecurity
April 21, 2026 at 2:27 PM
May 18, 2025 at 1:49 PM
March 6, 2025 at 3:18 PM
As far as I can tell, ContentSecurityPolicy (required by PCI) is a farce.

Braintree requires 'unsafe-inline'. So does Spreedly.

The only gateway I've found that has good docs AND a sane CSP suggestion is Stripe: docs.stripe.com/security/gui...
February 5, 2025 at 2:39 PM
tengo que integrar sus diferentes métodos, como `contentSecurityPolicy` y `xssFilter`, y listo. La seguridad no debe ser un lujo, y Helmet lo hace accesible. ¡Pruébalo!
March 26, 2025 at 7:00 PM
Hoy quiero hablarles de una herramienta que se ha vuelto indispensable en mis proyectos: helmet.js. Esta librería me ayuda a reforzar la seguridad de mis APIs al establecer cabeceras HTTP adecuadas. Al usar métodos como `set`, `contentSecurityPolicy` y `hsts`, puedo proteger mis aplicaciones contra
March 26, 2025 at 12:00 PM
Learn how CSP blocks reflected XSS in practice, why it does not replace escaping, and why it acts as a browser-enforced contract. #contentsecuritypolicy
CSP is Not Just a Header — It’s a Contract With the Browser
hackernoon.com
June 26, 2026 at 5:42 AM