Quiz

What are some common security headers and their purpose?

Topics
JavaScriptSecurity

TL;DR

Security headers are HTTP response headers that help protect web applications from various attacks. Some common security headers include:

  • Content-Security-Policy (CSP): Helps mitigate cross-site scripting (XSS) and other code injection attacks by restricting allowed content sources. It is a defense-in-depth control, not a replacement for safe output handling.
  • X-Content-Type-Options: Prevents MIME type sniffing by instructing the browser to follow the declared Content-Type.
  • Strict-Transport-Security (HSTS): Enforces secure (HTTPS) connections to the server.
  • Content-Security-Policy: frame-ancestors ...: Controls which sites may embed the page, helping prevent clickjacking. X-Frame-Options is a narrower legacy fallback.
  • Referrer-Policy: Controls how much referrer information is included with requests.
  • Permissions-Policy: Enables or disables selected browser capabilities for the page and embedded frames.

Common security headers and their purpose

Content-Security-Policy (CSP)

The Content-Security-Policy header helps prevent cross-site scripting (XSS) and other code injection attacks by specifying which content sources are allowed to be loaded on the web page. For example:

Content-Security-Policy: default-src 'self'; img-src 'self' https://example.com; script-src 'self' 'nonce-r4nd0m'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'

This policy defaults to same-origin resources, permits images from one additional origin, and permits inline scripts only when their nonce attribute matches the per-response nonce. It also blocks plugins, base-URL injection, and framing. Avoid adding 'unsafe-inline' merely to make a policy pass, because it substantially weakens script protection.

X-Content-Type-Options

The X-Content-Type-Options header prevents MIME type sniffing by instructing the browser to follow the declared Content-Type. This helps mitigate attacks based on content type misinterpretation. The most common value is nosniff:

X-Content-Type-Options: nosniff

Strict-Transport-Security (HSTS)

The Strict-Transport-Security header enforces secure (HTTPS) connections to the server. It instructs the browser to only interact with the site using HTTPS, even if the user attempts to access it via HTTP. For example:

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

This policy tells the browser to enforce HTTPS for one year (max-age=31536000), including all subdomains (includeSubDomains), and allows the site to be included in browsers' HSTS preload lists (preload).

Framing policy

The CSP frame-ancestors directive is the modern, flexible way to control who can embed a page. X-Frame-Options remains useful as a legacy fallback; its common values are DENY and SAMEORIGIN:

X-Frame-Options: DENY

This policy prevents the page from being displayed in a frame, iframe, or object.

Legacy: X-XSS-Protection

X-XSS-Protection controlled old browser XSS auditors. Modern browsers ignore it, and the filters could introduce vulnerabilities of their own. Do not treat it as an XSS defense; deploy context-aware output handling, a strong CSP, and preferably Trusted Types where appropriate.

X-XSS-Protection: 1; mode=block

Some legacy browsers interpret this as enabling their filter and blocking a suspected response. Current applications generally omit the header or set X-XSS-Protection: 0 to disable problematic legacy behavior.

Referrer-Policy

The Referrer-Policy header controls how much referrer information is included with requests. It helps protect user privacy and can prevent information leakage. Common values include no-referrer, no-referrer-when-downgrade, and strict-origin-when-cross-origin:

Referrer-Policy: no-referrer

This policy ensures that no referrer information is sent with requests.

Permissions-Policy

Permissions-Policy restricts access to capabilities such as camera, microphone, geolocation, and fullscreen, including for embedded frames:

Permissions-Policy: camera=(), microphone=(), geolocation=(self)

Further reading

Exercises

Check your understanding
Beta
Check your understanding Exercise 1 of 2
Check your understanding Exercise 1 of 2

Which security-header mappings are correct? Select all that apply.