HTTP Header Series: Content-Security-Policy
In our opening to this series, we discussed some of the reasons for Security Headers. In this post we will describe in more detail the Content-Security-Policy header that allows web site administrators to control resources the user agent is allowed to load for a given page. This header is critical is defending against cross-site scripting attacks.
Optimizely
Sitecore
Umbraco