A CSP ( ) is used to detect and mitigate certain types of website related attacks like and data injections. Content Security Policy XSS The implementation is based on an header called . HTTP Content-Security-Policy Learn more General knowledge Content Security Policy on Wikipedia Technical knowledge Content Security Policy documentation on MDN View Previous Terms: Block cipher mode of operation Certificate authority Challenge-response authentication Cipher Cipher suite Ciphertext CORS CORS-safelisted request header CORS-safelisted response header Cross-site scripting Cryptanalysis Cryptographic hash function Cryptography CSRF Decryption Digital certificate DTLS (Datagram Transport Layer Security) Encryption Forbidden header name Forbidden response header name Hash HMAC HPKP HSTS HTTPS Key MitM OWASP Preflight request Public-key cryptography Reporting directive Robots.txt Same-origin policy Session Hijacking SQL Injection Symmetric-key cryptography TOFU Transport Layer Security (TLS) Credits Source: https://developer.mozilla.org/en-US/docs/Glossary/CSP Published under license Open CC Attribution ShareAlike 3.0