Recipe 10-1: Implementing Content Security Policy (CSP)
This recipe shows you how to use ModSecurity to set a CSP for clients and monitor for policy violation reports.
Ingredients
- OWASP AppSensor
- Suspicious Client-side Behavior
- OWASP ModSecurity Core Rule Set (CRS)
- modsecurity_crs_10_setup.conf
- modsecurity_crs_42_csp_enforcement.conf
- Apache
- ModSecurity
- REQUEST_HEADERS variable
- REQUEST_BODY variable
- @validateByteRange operator
- setvar action
- setenv action
Content Security Policy (CSP)
Mozilla has developed a fantastic security capability in the Firefox web browser called Content Security Policy (CSP), which it describes as follows: