What are some common security headers and their purpose?
TL;DR
Security headers are HTTP response headers that help protect web applications from various attacks. Some common security headers include:
Content-Security-Policy (CSP): Helps mitigate cross-site scripting (XSS) and other code injection attacks by restricting allowed content sources. It is a defense-in-depth control, not a replacement for safe output handling.X-Content-Type-Options: Prevents MIME type sniffing by instructing the browser to follow the declaredContent-Type.Strict-Transport-Security (HSTS): Enforces secure (HTTPS) connections to the server.Content-Security-Policy: frame-ancestors ...: Controls which sites may embed the page, helping prevent clickjacking.X-Frame-Optionsis a narrower legacy fallback.Referrer-Policy: Controls how much referrer information is included with requests.Permissions-Policy: Enables or disables selected browser capabilities for the page and embedded frames.
Common security headers and their purpose
Content-Security-Policy (CSP)
The Content-Security-Policy header helps prevent cross-site scripting (XSS) and other code injection attacks by specifying which content sources are allowed to be loaded on the web page. For example:
Content-Security-Policy: default-src 'self'; img-src 'self' https://example.com; script-src 'self' 'nonce-r4nd0m'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'
This policy defaults to same-origin resources, permits images from one additional origin, and permits inline scripts only when their nonce attribute matches the per-response nonce. It also blocks plugins, base-URL injection, and framing. Avoid adding 'unsafe-inline' merely to make a policy pass, because it substantially weakens script protection.
X-Content-Type-Options
The X-Content-Type-Options header prevents MIME type sniffing by instructing the browser to follow the declared Content-Type. This helps mitigate attacks based on content type misinterpretation. The most common value is nosniff:
X-Content-Type-Options: nosniff
Strict-Transport-Security (HSTS)
The Strict-Transport-Security header enforces secure (HTTPS) connections to the server. It instructs the browser to only interact with the site using HTTPS, even if the user attempts to access it via HTTP. For example:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
This policy tells the browser to enforce HTTPS for one year (max-age=31536000), including all subdomains (includeSubDomains), and allows the site to be included in browsers' HSTS preload lists (preload).
Framing policy
The CSP frame-ancestors directive is the modern, flexible way to control who can embed a page. X-Frame-Options remains useful as a legacy fallback; its common values are DENY and SAMEORIGIN:
X-Frame-Options: DENY
This policy prevents the page from being displayed in a frame, iframe, or object.
Legacy: X-XSS-Protection
X-XSS-Protection controlled old browser XSS auditors. Modern browsers ignore it, and the filters could introduce vulnerabilities of their own. Do not treat it as an XSS defense; deploy context-aware output handling, a strong CSP, and preferably Trusted Types where appropriate.
X-XSS-Protection: 1; mode=block
Some legacy browsers interpret this as enabling their filter and blocking a suspected response. Current applications generally omit the header or set X-XSS-Protection: 0 to disable problematic legacy behavior.
Referrer-Policy
The Referrer-Policy header controls how much referrer information is included with requests. It helps protect user privacy and can prevent information leakage. Common values include no-referrer, no-referrer-when-downgrade, and strict-origin-when-cross-origin:
Referrer-Policy: no-referrer
This policy ensures that no referrer information is sent with requests.
Permissions-Policy
Permissions-Policy restricts access to capabilities such as camera, microphone, geolocation, and fullscreen, including for embedded frames:
Permissions-Policy: camera=(), microphone=(), geolocation=(self)
Further reading
- MDN Web Docs: HTTP headers
- OWASP Secure Headers Project
- Content Security Policy (CSP) - MDN Web Docs
- Strict-Transport-Security (HSTS) - MDN Web Docs