DrupalCon Seattle 2019: Is your site really safe from XSS?
About this talk
This talk focuses on Content Security Policy (CSP) as a crucial layer in web security, which aims to safeguard websites and users from threats such as cross-site scripting (XSS) and data exfiltration. The speaker discusses the most significant risks and the CSP options available to mitigate them, alongside an overview of the current state of the CSP specification and its browser support. Attendees will learn how to implement and monitor the effectiveness of a CSP, as well as the challenges posed by existing modules, frontend libraries, and third-party services. This session is particularly beneficial for site builders and developers, providing them with essential knowledge to effectively use the Content Security Policy for their websites.