大型Web项目可用性提升 零脚本错误的实战 郭林烁 2017.10������ CSP ��� ���� �������� ������ 1 CSP (Content Security Policy) HTML Meta �� HTTP Header � ��� �� CSP ���� CSP ���� 2 2 CSP �� 1 Content-Security-Policy Content-Security-Policy-Report-Only ��������� ������� �� �� ���� ���� 3 ��������� ������������ ������“��”���� 5 ���� � ���� 1 ������������� CGI���� ����� 6 �� ����������� �������� ��������� �� Web �� ������� �� ���� ������� 1 �� 2 ���� �XSS���-CSP������ https://github.com/joeyguo/blog/issues/5 ����������-�����Script error� ����������-����������0 码力 | 62 页 | 7.09 MB | 1 年前3
Apache Wicket 10.x Reference Guide. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 246 22.6. Content Security Policy (CSP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . application requirements. 22.6. Content Security Policy (CSP) In Wicket 9 support for a Content Security Policy (or CSP) has been added. CSP is an added layer of security that helps to detect and mitigate data theft to site defacement to distribution of malware. See MDN for more information on CSP. The default CSP set by Wicket is very strict. It requires all scripts and stylesheets to be rendered 2480 码力 | 336 页 | 7.16 MB | 1 年前3
Apache Wicket 9.x Reference Guide. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245 22.6. Content Security Policy (CSP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . application requirements. 22.6. Content Security Policy (CSP) In Wicket 9 support for a Content Security Policy (or CSP) has been added. CSP is an added layer of security that helps to detect and mitigate data theft to site defacement to distribution of malware. See MDN for more information on CSP. The default CSP set by Wicket is very strict. It requires all scripts and stylesheets to be rendered 2470 码力 | 335 页 | 7.15 MB | 1 年前3
Jupyter Notebook 5.7.5 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 155 页 | 1.71 MB | 1 年前3
Jupyter Notebook 5.7.0 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 145 页 | 1.83 MB | 1 年前3
Jupyter Notebook 5.7.3 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 155 页 | 1.86 MB | 1 年前3
Jupyter Notebook 5.7.6 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 155 页 | 1.71 MB | 1 年前3
Jupyter Notebook 5.7.1 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 145 页 | 1.82 MB | 1 年前3
Jupyter Notebook 5.7.4 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 155 页 | 1.86 MB | 1 年前3
Jupyter Notebook 5.7.2 Documentationimprovements (PR #3368) • Set notebook to dirty state after change to kernel metadata (PR #3350) • Use CSP header to treat served files as belonging to a separate origin (PR #3341) • Don’t install gettext ‘No proxy for’ field. 9.5.2 Content-Security-Policy (CSP) Certain security guidelines recommend that servers use a Content-Security-Policy (CSP) header to prevent cross-site scripting vulnerabilities communication). Jupyter uses WebSockets for interacting with kernels, so when you visit a server with such a CSP, your browser will block attempts to use wss, which will cause you to see “Connection failed” messages0 码力 | 145 页 | 1.83 MB | 1 年前3
共 71 条
- 1
- 2
- 3
- 4
- 5
- 6
- 8













