Security headers and TLS
30 procedures covering CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy. Out of scope here: penetration testing, vulnerability scanning, auth flows.
Security Headers
- How to check CSP header
- How to check if a site is vulnerable to clickjacking
- How to check permissions-policy header
- How to check referrer-policy header
- How to check security headers
- How to check subresource integrity
- How to check X-Content-Type-Options
- How to check X-Frame-Options
- X-XSS-Protection deprecated