Web & CMS

What is CSP (Content-Security-Policy)

What it is

A site header that tells the browser where fonts, scripts and images may be loaded from. The browser blocks everything else: foreign code cannot be slipped into the page, and the page does not call other people's servers.

How we use it

On the demo stand for a museum complex website the default-src 'self' policy forbids every external address: fonts, images and the map snapshot are on our own server, and the number of external loads can be checked right in the viewer's browser.

Where it helps a business

  • The site must open under any access restrictions, without calling foreign services.
  • Nobody should be able to slip a foreign script into the page and steal visitors' data.
  • You need to show, provably, that the page goes nowhere else.

How we use it

On the museum complex website demo stand the default-src 'self' policy forbids the browser any foreign address. Fonts (24 families, 218 styles under a free licence), images, video and the map snapshot live on our server. An "External loads" button in the presentation panel counts requests right in the viewer's browser. nginx serves the CSP policy together with other security headers.

Common problems

  • Analytics counters. External counters clash with a strict policy. On the demo the analytics counter runs in "showcase" mode and only writes events to the panel's log, while in live mode it stays silent until cookie consent; session replay is off because it records what is typed into form fields.
  • Everything has to be hosted yourself. Fonts, maps and videos must live on your own server, and their size needs watching.

When you do not need it

A strict no-external-address policy is overkill if the site deliberately uses external services such as payments, maps or widgets. Then the allowed addresses are listed explicitly.

โ† All terms

Need a website, a bot or automation?

Terms explained โ€” now let's get to work: tell us about the task and we'll turn it into a clear work plan.