Security
Strict Content Security Policy on a static site
Implementedenvironment:DeployedPersonal labSelf-reported · private sourcesite-strict-csp
Claim
Every page is static and served with a Content Security Policy that allows no inline script or style except inline scripts whose hashes are computed per route at build time, plus HSTS preload, behind nginx and Cloudflare.
Status
- implemented
- Capped at Implemented: the code, tests and records are private, so this is self-reported and cannot be verified publicly.
- deployed
- Running in a real, reachable environment I operate.
- personal lab
- My own projects. Public repositories carry CI-verified evidence; private ones are self-reported.
Source
A personal project whose repository is private and cannot be published. So this claim is self-reported: it stops at Implemented and links to no artifacts.
Limitations
- No external security review.
- Check it yourself: the response headers of any page on this site.