Skip to content
Ali Akbari
Menu

Security

Strict Content Security Policy on a static site

Implementedenvironment:DeployedPersonal labSelf-reported · private sourcesite-strict-csp

Claim

Every page is static and served with a Content Security Policy that allows no inline script or style except inline scripts whose hashes are computed per route at build time, plus HSTS preload, behind nginx and Cloudflare.

Status

implemented
Capped at Implemented: the code, tests and records are private, so this is self-reported and cannot be verified publicly.
deployed
Running in a real, reachable environment I operate.
personal lab
My own projects. Public repositories carry CI-verified evidence; private ones are self-reported.

Source

A personal project whose repository is private and cannot be published. So this claim is self-reported: it stops at Implemented and links to no artifacts.

Limitations

  • No external security review.
  • Check it yourself: the response headers of any page on this site.

Appears in