Quick reference for web security — security headers, cookie flags, CSP directives, and CORS config.
XSSCSRFHeadersCookies
Security Response Headers
| Header |
Recommended value |
Purpose |
| Content-Security-Policy | default-src 'self'; object-src 'none'; frame-ancestors 'none' | Mitigate XSS & injection |
| Strict-Transport-Security | max-age=63072000; includeSubDomains; preload | Force HTTPS |
| X-Content-Type-Options | nosniff | Block MIME sniffing |
| X-Frame-Options | DENY | Legacy clickjacking |
| Referrer-Policy | strict-origin-when-cross-origin | Limit Referer leakage |
| Permissions-Policy | geolocation=(), camera=() | Disable unused APIs |
Cookie Flags
| Flag |
Effect |
| HttpOnly | Hidden from JS; blunts XSS session theft |
| Secure | HTTPS only |
| SameSite | CSRF defense (Lax/Strict/None) |
| __Host- prefix | Locks Secure + path=/ + no Domain |
Hardened Set-Cookie
Set-Cookie: __Host-session=abc; Path=/; Secure; HttpOnly; SameSite=Lax
SameSite Values
| Value |
Behavior |
Use for |
| Strict | Never sent cross-site | Banking / high-value |
| Lax | Sent on top-level GET nav only (default) | Most sessions |
| None | Always sent; requires Secure | Legit cross-site embeds |
CSP Directive Quick Reference
| Directive |
Controls |
| default-src | Fallback for all fetch types |
| script-src | JS sources; use 'nonce-...' |
| object-src | Plugins; set 'none' |
| base-uri | Restrict <base>; set 'none' |
| frame-ancestors | Who can frame you (clickjacking) |
| connect-src | fetch/XHR/WebSocket targets |
Strict Starter Policy
default-src 'self'; script-src 'self' 'nonce-{{n}}';
object-src 'none'; base-uri 'none'; frame-ancestors 'none';
upgrade-insecure-requests
CORS Config
// Allowlist origins; NEVER reflect Origin with credentials.
const ALLOWED = new Set(['https://app.example.com']);
if (ALLOWED.has(req.headers.origin)) {
res.setHeader('Access-Control-Allow-Origin', req.headers.origin);
res.setHeader('Access-Control-Allow-Credentials', 'true');
res.setHeader('Access-Control-Allow-Methods', 'GET,POST');
res.setHeader('Vary', 'Origin');
}
// '*' cannot be combined with credentials.
XSS Sink / Encoding
| Context / Sink |
Safe approach |
| HTML body | HTML-encode / use textContent |
| HTML attribute | Attribute-encode + quote |
innerHTML | Sanitize with DOMPurify |
href/src URL | Allowlist scheme (block javascript:) |
| JS context | Pass via JSON/data attributes, not inline |
eval/Function | Avoid entirely |