{"id":3849,"date":"2026-10-10T12:00:38","date_gmt":"2026-10-10T05:00:38","guid":{"rendered":"https:\/\/sumberlaba.com\/index.php\/2026\/10\/10\/what-is-a-csp-in-web-security-a-practical-guide\/"},"modified":"2026-10-10T12:00:39","modified_gmt":"2026-10-10T05:00:39","slug":"what-is-a-csp-in-web-security-a-practical-guide","status":"publish","type":"post","link":"https:\/\/sumberlaba.com\/index.php\/2026\/10\/10\/what-is-a-csp-in-web-security-a-practical-guide\/","title":{"rendered":"What Is a CSP in Web Security? A Practical Guide"},"content":{"rendered":"<h1>What Is a CSP in Web Security? A Practical Guide<\/h1>\n<p>Content Security Policy (CSP) is an HTTP response header that tells the browser which resources a page may load. It&#8217;s a primary defense against cross-site scripting (XSS), clickjacking, and data injection. Instead of trusting every script that appears on the page, you declare an allowlist \u2014 and the browser blocks everything else.<\/p>\n<p>A CSP is sent as a header such as <code>Content-Security-Policy: default-src 'self'<\/code>. Any resource not permitted by the policy simply won&#8217;t load or execute, which stops injected scripts from stealing cookies or tokens.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/sumberlaba.com\/wp-content\/uploads\/2026\/10\/article-1791608435434.jpg\" alt=\"Article illustration\" style=\"display:block;margin:20px auto;max-width:100%;height:auto;border-radius:8px;\" \/><\/p>\n<h2>How CSP Works<\/h2>\n<p>Each directive controls one resource type: scripts, styles, images, fonts, frames, or network connections. The browser checks every request against the policy before making it.<\/p>\n<h2>Key Directives<\/h2>\n<ul>\n<li><strong>default-src<\/strong> \u2014 fallback for all resource types<\/li>\n<li><strong>script-src<\/strong> \u2014 the most important; controls JavaScript<\/li>\n<li><strong>style-src<\/strong> \u2014 limits CSS sources<\/li>\n<li><strong>connect-src<\/strong> \u2014 restricts fetch, XHR, and WebSockets<\/li>\n<li><strong>frame-ancestors<\/strong> \u2014 replaces X-Frame-Options<\/li>\n<\/ul>\n<h2>Rolling Out CSP Safely<\/h2>\n<p>Start with <code>Content-Security-Policy-Report-Only<\/code>, which logs violations without blocking anything. Fix what breaks, then switch to enforcing mode. Avoid <em>&#8216;unsafe-inline&#8217;<\/em> and <em>&#8216;unsafe-eval&#8217;<\/em> \u2014 they weaken the policy dramatically. Use nonces or hashes for inline scripts, and add a <strong>report-uri<\/strong> endpoint to monitor attacks in production.<\/p>\n<h2>Conclusion<\/h2>\n<p>CSP won&#8217;t fix vulnerable code, but it&#8217;s a powerful second layer of defense. Deploy it in report-only mode, tighten it gradually, and you&#8217;ll neutralize most XSS attempts before they ever run.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What Is a CSP in Web Security? A Practical Guide Content Security Policy (CSP) is an HTTP response header that tells the browser which resources a page may load. It&#8217;s a primary defense against cross-site scripting (XSS), clickjacking, and data injection. Instead of trusting every script that appears on the page, you declare an allowlist &hellip; <\/p>\n","protected":false},"author":2716,"featured_media":3848,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3849","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-category"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/users\/2716"}],"replies":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/comments?post=3849"}],"version-history":[{"count":1,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3849\/revisions"}],"predecessor-version":[{"id":3850,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/posts\/3849\/revisions\/3850"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/media\/3848"}],"wp:attachment":[{"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/media?parent=3849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/categories?post=3849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sumberlaba.com\/index.php\/wp-json\/wp\/v2\/tags?post=3849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}