Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

HTTP Security Headers You Need To Have On Your Web Apps

NDC Conferences via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course explains how HTTP security headers protect websites and web applications from threats such as cross-site scripting and clickjacking. It demonstrates their effects before and after implementation and discusses safely retrofitting them into existing applications.

Syllabus

Intro
Audience
What are HTTP Headers?
What are HTTP Security Headers?
HTTP Strict Transport Security (HSTS)
Without HSTS
What's the issue?
What can happen?
With HSTS
HSTS Options
HSTS Preload List
HSTS Gotchas
HSTS Impact of Retrofitting on Existing A
Quick word on HTTPS
Cross-Site Scripting (XSS)
XSS Final Note
Content Security Policy (CSP) Options
CSP Impacting of Retrofitting to Existing
Browser Sniffing Protection X-Content-Type
XCTO Impact of Retrofitting to Existing AS
Referer Header background
and even JIRA/Confluence/OWA
Referrer-Policy
Feature-Policy Is Experimental
How do I test my website?
Takeaways
Resources

Taught by

NDC Conferences

Reviews

Start your review of HTTP Security Headers You Need To Have On Your Web Apps

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.