Security · What the page may load, run and send

Secure transmission and content policies-style app

Illustrative system design for a what the page may load, run and send app like Secure transmission and content policies: 4 topics to read, from requirements to deep dives.

Illustrative design, not Secure transmission and content policies’s actual implementation. Arrowbox is not affiliated with Secure transmission and content policies’s owner. Disclaimer

Start with HTTPS and HSTS Sign in to start readingUpdated 2 Oct 2026

Core

  • Encrypted transport and HSTSBeginner · 30 min read · Sign in to read

    HTTPS makes the network unable to read or change a page, but only if every request uses it: HSTS removes the plain-HTTP first hop, and mixed-content rules stop an HTTPS page from pulling in HTTP resources.

  • Rendering untrusted contentIntermediate · 31 min read · Sign in to read

    Cross-site scripting happens when data a user supplied reaches a place where the browser treats it as code; the defense is to keep data in text sinks, encode for the context when it cannot, and sanitize the rare HTML that must stay HTML.

  • Content Security Policy and SRIAdvanced · 31 min read · Sign in to read

    A Content Security Policy tells the browser which scripts, styles, frames and connections a page may use, so an injection that slips past escaping still cannot run; Subresource Integrity pins third-party files to the exact bytes you reviewed; frame-ancestors decides who may frame you.

  • Cross-origin requests, CORS and CSRFIntermediate · 35 min read · Sign in to read

    The same-origin policy stops other sites from reading your responses but not from sending requests; CORS is how a server opts in to cross-origin reads, and CSRF defenses are how it refuses cross-site writes that ride the user's cookies.