# Kan ik een snippet toevoegen aan de header?

**URL:** https://meta.discourse.org/t/can-i-add-a-snippet-to-the-header/254242
**Category:** Support
**Created:** [6 februari 2023 om 16:42 UTC](https://meta.discourse.org/t/can-i-add-a-snippet-to-the-header/254242 "2023-02-06T16:42:44Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![southpaw](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/southpaw/32/79352_2.png) [@southpaw](https://meta.discourse.org/u/southpaw)
#### Post date: [7 februari 2023 om 04:25 UTC](https://meta.discourse.org/t/can-i-add-a-snippet-to-the-header/254242/4 "2023-02-07T04:25:12Z")

</div>

Hi @dafegosa,

I _think_ option 1 in the site settings as described in this section of the Content Security Policy topic, might work for what you’re trying to do, but if not, there’s lots of good info in the topic:

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243#extending-the-default-csp-9):
>
> bookmark This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. person_raising_hand Required user level: Administrator Summary Content Security Policy (CSP) is a crucial security feature in Discourse that helps protect against Cross-Site Scripting (XSS) and other injection attacks. This guide covers the basics of CSP, how it’s implemented in Discourse, and how to c…

---

_[View the full topic](https://meta.discourse.org/t/can-i-add-a-snippet-to-the-header/254242)._
