Last Call: Content Security Policy 1.0

Author(s) and publish date

Published:

The Web Application Security Working Group has published a Last Call Working Draft of Content Security Policy 1.0. This document defines Content Security Policy, a mechanism web applications can use to mitigate a broad class of content injection vulnerabilities, such as cross-site scripting (XSS). Content Security Policy is a declarative policy that lets the authors (or server administrators) of a web application restrict from where the application can load resources. Comments are welcome through 24 August. Learn more about the Security Activity.

Related RSS feed