The ten steps
About an hour end to end. Every step stands on its own, so stopping after step 3 still leaves you better off than when you started — you will have a policy deployed and reporting.
- What CSP actually does3 min
- Deploy one today and break nothing5 min
- Read a violation report5 min
- The directives that matter6 min
- Why allowlists fail6 min
- Nonces and strict-dynamic7 min
- How nonces go wrong5 min
- Third parties and the real rollout6 min
- The four everyone forgets5 min
- Ship it5 min
No account, no progress bar, nothing saved. Bookmark wherever you get to.