Magazine · · 2 min read
A security policy without the back door
Almost every website grants itself 'unsafe-inline' — the exception that voids the whole rule. What it costs to do without, and what you get in return.
What a Content Security Policy promises
A promise travels with the server's first response: the Content Security Policy. It tells the browser where this site may load scripts, styles and images from — and the browser enforces it. If an attacker manages to smuggle foreign code into a page, the browser simply refuses to run it, because the policy forbids it. The policy is the safety net for the day every other precaution has failed.
Provided it is meant seriously. Most policies contain two words that cut the net: 'unsafe-inline'.
The exception that eats the rule
'unsafe-inline' permits code and styles written directly into the HTML. It sounds harmless and is convenient — almost every tool and site builder demands it. But injected code sits exactly there: in the HTML. A policy with this exception forbids the routes an attacker does not need and permits the one he uses. The name is honest: unsafe.
Our policy does without the exception — for scripts and for styles. Everything the site runs or styles lives in files of its own on its own domain. The HTML contains not a single style attribute and not a single embedded script block.
What that demands day to day
Doing without is not a setting but a way of building. Spacing and colours that would once have slipped into the HTML as style attributes become named classes in the stylesheet. Product colours that come from data are generated at build time as classes — not as attributes in the HTML. And a check stands guard: should an inline style reappear anywhere, it fires before the browser would discard it.
That is the true value of the strict policy: it forces an order that would be right even without it.
That is the true value of the strict policy: it forces an order that would be right even without it. Refusing the exception means refusing the disorder it would have to cover.
The rest of the headers
The policy does not stand alone. No embedding in foreign pages, no content-type guessing, frugal referrers, no permissions for camera, microphone or location that nobody needs. Each of these headers is one line of configuration — together they are the difference between a site that looks safe and one that puts it in writing to the browser. Verifiable by anyone, with one look at the server's response.
Next
This is how we work — and what comes of it.
What this text describes sits inside every product under this roof. Looking beats reading on.
Exactly this is inside:
Languages & learningEveryLinguaThe whole grammar of a language — explained in your own, level by level.
Property & financeImmoZahlWhat a property actually carries — worked out before anyone signs.
Financial knowledgeStrikeAndYieldFinancial products explained — from the first sentence to the pricing formula.
Travel & adviceIndigo AtollThe islands of the Indian Ocean, sorted by what you are actually looking for.
More articles
Citizenship test in Germany: how many questions, how many right?
33 questions, 60 minutes, a pass from 17 correct answers. What sits behind these three numbers, where the questions come from — and why the whole test can be learned in advance.
Read the articleGerman recreational boat licence (sea): questions and pass marks
30 of 285 questions, 60 minutes, two parts scored separately. Why the spread of your mistakes matters more than their number — and what comes on top of the theory exam.
Read the articleThe English simple present, explained for German speakers
The basic present tense in English has exactly one trap: the third person singular. When the simple present is used, how questions and negatives are built — and why the -s feels so illogical.
Read the article