ToolypetMCP
advanced6 minutescross hub

Content Security Pipeline

Secure web content delivery with CSP, SRI for CDN resources, CORS configuration, and security audit.

cspsricorscdnsecurity

이 레시피 활용 시점

Protect your website from XSS, CDN supply chain attacks, and unauthorized API access. Essential for any production site serving content from multiple origins.

단계

1

Create Content Security Policy

프롬프트:Generate CSP allowing self, Google Fonts, CDN scripts, and inline styles for a production site
2

Audit the CSP quality

프롬프트:Evaluate the CSP for security weaknesses and grade it
3

Protect CDN resources

프롬프트:Generate SRI hashes for all CDN-loaded JavaScript and CSS files
4

Set up cross-origin policies

프롬프트:Configure CORS headers for the CDN and API endpoints

자주 묻는 질문

What is SRI and why does it matter?

Subresource Integrity (SRI) ensures CDN-hosted scripts haven't been tampered with. If a CDN is compromised, SRI prevents the modified script from executing on your site.

Can CSP break my website?

Yes, an overly strict CSP can block legitimate resources. Start with Content-Security-Policy-Report-Only to log violations without blocking, then tighten gradually.

관련 레시피