Monday, July 3, 2017

How to Get Started with Your Website Content Security Policy

This article is part of a series created in partnership with SiteGround. Thank you for supporting the partners who make SitePoint possible.

The web is based on a "same-origin" policy. Only code at mysite.com can access mysite.com's data in cookies, localStorage, Ajax requests etc. It is isolated from other domains so any access attempts from evilsite.com will be rejected.

Unfortunately, it's never that simple. Modern websites are complex and load a variety of third-party components, styles and scripts. A script loaded from another domain runs in the context of the current page and can do whatever it likes. That social networking button could monitor visitors, hijack login cookies, change page content and more. Even if you trust the third-party site, you could become victim to a man-in-the-Middle attack where the script is changed before it reaches you. Alternatively, it could permit users to launch their own Cross Site Scripting attacks (XXS).

By default, browsers implement an anything-goes approach. Fortunately, it's possible to apply restrictions using a Content Security Policy (CSP) which prevent unexpected security issues. A CSP tells the browser what's permitted, e.g. run JavaScript at mysite.com but only from files and not inline <script> tags.

Continue reading %How to Get Started with Your Website Content Security Policy%


by Craig Buckler via SitePoint

Live & Wired

Live & Wired

Long-scrolling Landing Page with a fun header background video for social content agency, Live & Wired.

by Rob Hope via One Page Love

Fitness Point

Fitness Point

'Fitness Point' is a niche One Page WordPress theme crafted for a Gym, Fitness Instructor or Sports Club. Features include services, class schedule, image gallery (with category filter), featured products with WooCommerce integration, pricing table, big image testimonial slider, blog feed and a contact form.

by Rob Hope via One Page Love

20 Best HTML5 Game Templates of 2017

Code a Real-Time NativeScript App: SQLite

Thumbsupjobs

Thumbsupjobs

Clean little One Pager for website/app job middle man, Thumbsupjobs. Nice bright blue gradient but would have liked to see some testimonials to strengthen the service pitch.

by Rob Hope via One Page Love

How to Create Instagram Stories Ads for Traffic and Conversions

Do you use Instagram stories? Looking for ways to increase your conversions? Instagram Stories ads have expanded to include four objectives that let marketers drive specific goal-oriented conversions. In this article, you’ll discover how to use Instagram Stories ads to improve your marketing results. What Are Instagram Stories Ad Objectives? Instagram story ads play between [...]

This post How to Create Instagram Stories Ads for Traffic and Conversions first appeared on .
- Your Guide to the Social Media Jungle


by Ana Gotter via