contentintech

Web Security Cheatsheet

Quick reference for web security — security headers, cookie flags, CSP directives, and CORS config.

XSSCSRFHeadersCookies
NotesCheatsheet

Security Response Headers

Header Recommended value Purpose
Content-Security-Policydefault-src 'self'; object-src 'none'; frame-ancestors 'none'Mitigate XSS & injection
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preloadForce HTTPS
X-Content-Type-OptionsnosniffBlock MIME sniffing
X-Frame-OptionsDENYLegacy clickjacking
Referrer-Policystrict-origin-when-cross-originLimit Referer leakage
Permissions-Policygeolocation=(), camera=()Disable unused APIs

Cookie Flags

Flag Effect
HttpOnlyHidden from JS; blunts XSS session theft
SecureHTTPS only
SameSiteCSRF defense (Lax/Strict/None)
__Host- prefixLocks Secure + path=/ + no Domain

Hardened Set-Cookie

Set-Cookie: __Host-session=abc; Path=/; Secure; HttpOnly; SameSite=Lax

SameSite Values

Value Behavior Use for
StrictNever sent cross-siteBanking / high-value
LaxSent on top-level GET nav only (default)Most sessions
NoneAlways sent; requires SecureLegit cross-site embeds

CSP Directive Quick Reference

Directive Controls
default-srcFallback for all fetch types
script-srcJS sources; use 'nonce-...'
object-srcPlugins; set 'none'
base-uriRestrict <base>; set 'none'
frame-ancestorsWho can frame you (clickjacking)
connect-srcfetch/XHR/WebSocket targets

Strict Starter Policy

default-src 'self'; script-src 'self' 'nonce-{{n}}';
object-src 'none'; base-uri 'none'; frame-ancestors 'none';
upgrade-insecure-requests

CORS Config

// Allowlist origins; NEVER reflect Origin with credentials.
const ALLOWED = new Set(['https://app.example.com']);
if (ALLOWED.has(req.headers.origin)) {
  res.setHeader('Access-Control-Allow-Origin', req.headers.origin);
  res.setHeader('Access-Control-Allow-Credentials', 'true');
  res.setHeader('Access-Control-Allow-Methods', 'GET,POST');
  res.setHeader('Vary', 'Origin');
}
// '*' cannot be combined with credentials.

XSS Sink / Encoding

Context / Sink Safe approach
HTML bodyHTML-encode / use textContent
HTML attributeAttribute-encode + quote
innerHTMLSanitize with DOMPurify
href/src URLAllowlist scheme (block javascript:)
JS contextPass via JSON/data attributes, not inline
eval/FunctionAvoid entirely

Section navigation