FortiAppSec Cloud
FortiAppSec Cloud delivers unified application security and performance with WAF, bot protection, GSLB, DDoS mitigation, threat analytics, and CDN.
Srija_RedA
Staff
Staff
Article Id 309812
Description

This article describes how to add a Content Security Policy (CSP) header to prevent XSS and data injection attacks and explains the effects.

Scope FortiAppSec Cloud.
Solution

If there is an existing CSP header on the website or application and this policy on FortiAppSec Cloud under HTTP header security is enabled, FortiAppSec Cloud will replace the CSP header.

 

Simple Apache website before FortiAppSec Cloud:

 

fweb1.png

 

FortiAppSec Cloud CSP header policy:

 

httpheadersec.png

 

After FortiAppSec Cloud:

 

fweb2.png