<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Ask Ghassem - Recent questions tagged csp</title>
<link>https://ask.ghassem.com/tag/csp</link>
<description>Powered by Question2Answer</description>
<item>
<title>When should one include a Content Security Policy?</title>
<link>https://ask.ghassem.com/189/when-should-one-include-a-content-security-policy</link>
<description>&lt;p&gt;Content Security Policy (CSP) is promoted as a way to mitigate content injection vulnerabilities including cross-site scripting. When making a website when should a CSP header be included and when is it of no use?&lt;/p&gt;

&lt;p&gt;I read &lt;a rel=&quot;nofollow&quot; href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP&quot;&gt;https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP &lt;/a&gt;&lt;/p&gt;

&lt;p&gt;which explained what CSP is, but I am still confused as to &lt;strong&gt;when&lt;/strong&gt; to use it.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
<category>Web Development</category>
<guid isPermaLink="true">https://ask.ghassem.com/189/when-should-one-include-a-content-security-policy</guid>
<pubDate>Fri, 28 Sep 2018 19:15:24 +0000</pubDate>
</item>
</channel>
</rss>