Blog
A Content-Security-Policy for a site with no third parties
With no CDN fonts, no analytics and no embeds, the policy collapses to default-src self. What that rules out, the one inline exception for noscript styles, and why the rest of the headers file is short.
Most security headers advice is about carving exceptions for the third parties a site depends on. Remove the third parties and the policy becomes a single line: scripts, styles, fonts, images and connections all from the site's own origin.
The exception we keep is inline styles, because the noscript fallback that reveals hidden content when JavaScript is off is a style block in the head. Frame ancestors are denied, the base URI is pinned, and forms can only post home.
All posts