The Content Security Policy (CSP) specifies from which sources the browser may load scripts, styles, images and other content for your site. This makes life much harder for injected scripts (XSS). ShieldCache sets the CSP for you - you will find it under Settings > Headers.
The three modes
- Off: no CSP from ShieldCache. A CSP from your server or the header template remains as before.
- Report only: The browser does not block anything, but reports every violation (Report-Only). Ideal for testing.
- Enforce: The browser blocks everything the policy does not allow and reports it.
Step by step: report first, then enforce
- Choose the Report only mode.
- Create directives. Start, for example, with
default-srcand the source'self'(your own domain), plusimg-srcwith'self'anddata:orscript-srcwithhttps://cdn.muster.de. Below each directive, the allowed keywords and schemes are listed for quick adding; invalid entries are explained as you type. - Click Save and then Apply.
- Check the reported violations for a few days. With Take over from reports, the customer area suggests the reported sources for the matching directive - only take over what your site really needs.
- Only when no more legitimate reports come in, switch to Enforce.
unsafe-inline and unsafe-eval
'unsafe-inline' and 'unsafe-eval' allow inline code and eval() respectively and remove a large part of the protection. Hashes ('sha256-...') or external files are better. Nonces and http:// sources are not possible.
Good to know
- With “Report only” or “Enforce”, ShieldCache replaces a CSP from your server. The ShieldCache error and check pages keep their own strict policy.
- Upgrade insecure requests to HTTPS (
upgrade-insecure-requests) follows the header template by default. When reporting, ShieldCache also sends this directive as an enforced policy, because Report-Only does not support it. - The preview shows the header exactly as visitors receive it - at most 4096 characters. If it becomes too long, combine sources, for example with
*.muster.de. - The browser reports violations to
/.shieldcache/csp-berichton your own domain.
Reported violations
The Reported violations card groups identical reports: directive, blocked source, page (without parameters), mode, count and last report. New reports appear after about 10 seconds, instantly with ↻. “Only since the last apply” hides older reports. No IP addresses are stored; entries expire 30 days after the last report.
Custom headers
- Set headers: name and value, for example
X-Frame-Options=DENYor aPermissions-Policy. Up to 20 headers. - Remove headers: headers that your server sends and that should not go out, for example
X-Powered-By. Up to 20.
How they work together: The header template replaces headers of the same name from your server. Custom headers are set last and win over the template and server; “Remove headers” also removes headers from the template. ShieldCache error pages do not receive them.
Blocked are headers that ShieldCache manages itself (such as Content-Security-Policy, Strict-Transport-Security, Alt-Svc), that concern the structure of the response (such as Content-Length) or that are security-critical (such as Set-Cookie, Location). The complete list can be expanded below the card.