Skip to content

Commit ec4a1c8

Browse files
authored
Add google CSP resources
/cc @mikispag
1 parent b37c6fa commit ec4a1c8

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

README.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@
77

88
The gem will automatically apply several headers that are related to security. This includes:
99
- Content Security Policy (CSP) - Helps detect/prevent XSS, mixed-content, and other classes of attack. [CSP 2 Specification](http://www.w3.org/TR/CSP2/)
10+
- https://csp.withgoogle.com
11+
- https://csp.withgoogle.com/docs/strict-csp.html
12+
- https://csp-evaluator.withgoogle.com
1013
- HTTP Strict Transport Security (HSTS) - Ensures the browser never visits the http version of a website. Protects from SSLStrip/Firesheep attacks. [HSTS Specification](https://tools.ietf.org/html/rfc6797)
1114
- X-Frame-Options (XFO) - Prevents your content from being framed and potentially clickjacked. [X-Frame-Options Specification](https://tools.ietf.org/html/rfc7034)
1215
- X-XSS-Protection - [Cross site scripting heuristic filter for IE/Chrome](https://msdn.microsoft.com/en-us/library/dd565647\(v=vs.85\).aspx)

0 commit comments

Comments
 (0)