Dab tsi yog qhov tsis zoo hauv kab hauv CSP?
Dab tsi yog qhov tsis zoo hauv kab hauv CSP?

Video: Dab tsi yog qhov tsis zoo hauv kab hauv CSP?

Video: Dab tsi yog qhov tsis zoo hauv kab hauv CSP?
Video: CCI Application 2024, Kaum ib hlis
Anonim

' tsis nyab xeeb - hauv kab ' Tso cai rau siv hauv kab cov peev txheej, xws li hauv kab cov ntsiab lus, javascript: URLs, hauv kab event handlers, thiab hauv kab cov ntsiab lus. Koj yuav tsum suav nrog cov lus qhia ib leeg. 'tsis muaj' Hais txog qhov khoob khoob; uas yog, tsis muaj URLs match.

Xav txog qhov no, ua li cas koj siv tsis zoo inline?

Cov tsis nyab xeeb - hauv kab kev xaiv yog siv thaum tsiv los yog rov sau dua hauv kab code hauv koj qhov chaw tam sim no tsis yog qhov kev xaiv tam sim no tab sis koj tseem xav tau siv CSP tswj hwm lwm yam (xws li khoom-src, tiv thaiv kev txhaj tshuaj thib peb js thiab lwm yam).

Ib sab saum toj no, Kuv yuav ua li cas rau CSP? Phau Ntawv Qhia Pib Ceev

  1. Ntxiv qhov nruj CSP Header rau koj qhov chaw.
  2. Sau npe rau ib tus as khauj dawb ntawm Report URI.
  3. Siv Daim Ntawv Qhia URI, mus rau CSP> Kuv Txoj Cai.
  4. Siv Daim Ntawv Qhia URI, mus rau CSP> Wizard.
  5. Hloov kho koj CSP nrog txoj cai tshiab tsim los ntawm Report URI.

Tom qab ntawd, ib tug kuj yuav nug, CSP Web yog dab tsi?

Cov ntsiab lus Security Policy ( CSP ) yog lub khoos phis tawj kev ruaj ntseg tus qauv qhia los tiv thaiv kev sib tsoo ntawm qhov chaw sau ntawv (XSS), clickjacking thiab lwm yam kev txhaj tshuaj tiv thaiv kab mob uas tshwm sim los ntawm kev tua cov ntsiab lus tsis zoo hauv kev ntseeg siab. web nplooj ntawv ntsiab lus.

Kuv yuav lov tes taw CSP li cas?

Nyem qhov txuas ntxiv icon rau lov tes taw CSP taub hau. Nyem qhov txuas ntxiv icon dua kom rov qhib dua CSP taub hau. Siv qhov no tsuas yog qhov chaw kawg nkaus xwb. Disabling CSP txhais tau tias ua tsis taus nta tsim los tiv thaiv koj los ntawm kev sau ntawv hla chaw.

Pom zoo: