DELISORIA
Auf Deutsch
Portfolio01Magazine02Contact03 Auf Deutsch DE
Back to all articles

Magazine · · 2 min read

A security policy without the back door

Almost every website grants itself 'unsafe-inline' — the exception that voids the whole rule. What it costs to do without, and what you get in return.

What a Content Security Policy promises

A promise travels with the server's first response: the Content Security Policy. It tells the browser where this site may load scripts, styles and images from — and the browser enforces it. If an attacker manages to smuggle foreign code into a page, the browser simply refuses to run it, because the policy forbids it. The policy is the safety net for the day every other precaution has failed.

Provided it is meant seriously. Most policies contain two words that cut the net: 'unsafe-inline'.

The exception that eats the rule

'unsafe-inline' permits code and styles written directly into the HTML. It sounds harmless and is convenient — almost every tool and site builder demands it. But injected code sits exactly there: in the HTML. A policy with this exception forbids the routes an attacker does not need and permits the one he uses. The name is honest: unsafe.

Our policy does without the exception — for scripts and for styles. Everything the site runs or styles lives in files of its own on its own domain. The HTML contains not a single style attribute and not a single embedded script block.

What that demands day to day

Doing without is not a setting but a way of building. Spacing and colours that would once have slipped into the HTML as style attributes become named classes in the stylesheet. Product colours that come from data are generated at build time as classes — not as attributes in the HTML. And a check stands guard: should an inline style reappear anywhere, it fires before the browser would discard it.

That is the true value of the strict policy: it forces an order that would be right even without it.

That is the true value of the strict policy: it forces an order that would be right even without it. Refusing the exception means refusing the disorder it would have to cover.

The rest of the headers

The policy does not stand alone. No embedding in foreign pages, no content-type guessing, frugal referrers, no permissions for camera, microphone or location that nobody needs. Each of these headers is one line of configuration — together they are the difference between a site that looks safe and one that puts it in writing to the browser. Verifiable by anyone, with one look at the server's response.