PolicyBuilder p = new PolicyBuilder(); p .default_src(CSP.NONE) .report_uri(CSPReporterServlet.URL); response.setHeader(CSP.Header.REPORT_ONLY, p.build());
To set a header that disallows loading of scripts except from social network widgets: PolicyBuilder p = new PolicyBuilder(); p .script_src( "https://apis.google.com", "https://platform.twitter.com") .frame_src( "https://plusone.google.com", "https://facebook.com", "https://platform.twitter.com"); response.setHeader(CSP.Header.SECURE, p.build());
|
|
|
|
|
|