Skip to content

Commit 39975be

Browse files
authored
Merge pull request #255 from righettod/master
add ref to https://cspbypass.com/
2 parents 261d08d + f00aa25 commit 39975be

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

tab_bestpractices.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -352,6 +352,8 @@ Cache-Control: no-store, max-age=0
352352

353353
## Prevent CSP bypasses
354354

355+
> 💡 This [online tool](https://cspbypass.com/) can be used to identify existing bypasses for a CSP policy.
356+
355357
This section describes some points, to keep in mind, during the creation of a [Content-Security-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) (called **CSP**) policy to prevent introducing bypasses.
356358

357359
🚩 Not every **[directives](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#directives)** fallback to the **[default-src](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/default-src)** directive when it is not specified in the CSP policy.

0 commit comments

Comments
 (0)