<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Web Security on CSP Guide</title>
    <link>https://csp-guide.com/tags/web-security/</link>
    <description>Recent content in Web Security on CSP Guide</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 08 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://csp-guide.com/tags/web-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CSP for HubSpot Chat Widget: Common Mistakes and Fixes</title>
      <link>https://csp-guide.com/posts/csp-for-hubspot-chat-widget/</link>
      <pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-hubspot-chat-widget/</guid>
      <description>Common CSP mistakes when deploying the HubSpot chat widget, plus practical fixes for script-src, connect-src, frame-src, styles, and CSP reporting.</description>
    </item>
    <item>
      <title>CSP for FullStory Product Analytics</title>
      <link>https://csp-guide.com/posts/csp-for-fullstory-product-analytics/</link>
      <pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-fullstory-product-analytics/</guid>
      <description>Set a safe Content Security Policy for FullStory product analytics with practical directives, code examples, and rollout tips.</description>
    </item>
    <item>
      <title>CSP for Email Templates and HTML Emails: Pros, Cons, Reality</title>
      <link>https://csp-guide.com/posts/csp-for-email-templates-and-html-emails/</link>
      <pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-email-templates-and-html-emails/</guid>
      <description>A practical comparison of CSP for email templates and HTML emails, including what works, what breaks, and safer patterns for developers.</description>
    </item>
    <item>
      <title>CSP for Custom Flag Systems: Pros, Cons, and Safer Patterns</title>
      <link>https://csp-guide.com/posts/csp-for-custom-flag-systems/</link>
      <pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-custom-flag-systems/</guid>
      <description>Compare CSP approaches for custom flag systems, with pros, cons, and practical policy examples for frontend teams shipping safely.</description>
    </item>
    <item>
      <title>CSP for Ruby on Rails: a real before-and-after case study</title>
      <link>https://csp-guide.com/posts/csp-for-ruby-on-rails/</link>
      <pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-ruby-on-rails/</guid>
      <description>A practical Rails CSP case study with before-and-after policies, nonce examples, third-party script fixes, and rollout advice.</description>
    </item>
    <item>
      <title>CSP and Browser Extensions: Common Mistakes to Fix</title>
      <link>https://csp-guide.com/posts/how-csp-works-with-browser-extensions/</link>
      <pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/how-csp-works-with-browser-extensions/</guid>
      <description>Common CSP mistakes with browser extensions, why they happen, and how to fix debugging confusion for real-world web apps.</description>
    </item>
    <item>
      <title>CSP for Educational Platforms and LMS</title>
      <link>https://csp-guide.com/posts/csp-for-educational-platforms-and-lms/</link>
      <pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-educational-platforms-and-lms/</guid>
      <description>Copy-paste CSP reference for educational platforms and LMS, with practical policies for video, SSO, SCORM, analytics, and embedded tools.</description>
    </item>
    <item>
      <title>CSP and SRI Together: Practical Reference and Examples</title>
      <link>https://csp-guide.com/posts/csp-and-subresource-integrity-sri-working-together/</link>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-and-subresource-integrity-sri-working-together/</guid>
      <description>Reference guide to using CSP and Subresource Integrity together, with copy-paste examples, deployment patterns, and common pitfalls.</description>
    </item>
    <item>
      <title>Common CSP Myths Debunked: Mistakes and Fixes</title>
      <link>https://csp-guide.com/posts/common-csp-myths-debunked/</link>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/common-csp-myths-debunked/</guid>
      <description>Common CSP myths that lead to weak policies, broken apps, and false confidence—plus practical fixes and real header examples.</description>
    </item>
    <item>
      <title>CSP for Next.js API Routes</title>
      <link>https://csp-guide.com/posts/csp-for-next-js-api-routes/</link>
      <pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-next-js-api-routes/</guid>
      <description>Learn how to set strong Content Security Policy headers for Next.js API routes, with code examples for Pages Router, App Router, and middleware.</description>
    </item>
    <item>
      <title>CSP Mistakes Government Sites Keep Making</title>
      <link>https://csp-guide.com/posts/csp-for-government-websites/</link>
      <pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://csp-guide.com/posts/csp-for-government-websites/</guid>
      <description>Common CSP mistakes on government websites, why they happen, and practical fixes for safer policies without breaking services.</description>
    </item>
  </channel>
</rss>
