CSP XSS. ( , , , , ) (http://caniuse.com/#search=csp).
XSS, . JavaScript, - Self-XSS (, facebook Chrome - ).
, - XSS. :
- Import data from third-party systems
- Migration data from the old system.
- Cookies and http.
If you have the appropriate data verification and encoding (server side), you can additionally apply a browser mechanism, such as: CSP, X-XSS-Protection or X-Content-Type-Options, to increase your confidence in the security of your system.
source
share