Mozilla previews Content Security Policy | Internet News

Mozilla previews Content Security Policy

Oct 1, 2009
1 minute read

sr-firefox3.jpg

From the

More Work For Web Developers

files:

In June of this year, Mozilla announced a new security effort called Content Security Policy (CSP) to help prevent Cross Site Scripting (XSS) attacks. Now here we are three months later and the first previews of CSP are now available.

The basic idea with CSP is that it is an attempt to help to validate that code running in a browser is authorized.

Mozilla has also set up a demo page where developers can test to see if their pages are being properly accessed by CSP.

In my view, CSP puts, increased (but not unrealistic) additional
burden on web developers to put in additional code snippets for CSP
validation. Instead of just enabling open access for all, developers will now have to think about which sections of their web page code and which scripts should be authorized to run and where.

The new preview according to Mozilla isn’t quote done by they’re close.

“The implementation is not quite complete so you may notice some small gaps between the preview builds and the spec,” Brandon Sterne
Security Program Manager at Mozilla blogged. “Most notably, HTTP redirects are not yet handled by CSP (but will be soon).”

Does this mean we’ll see CSP in Firefox 3.6?

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.