# Mitigate XSS Attacks with Content Security Policy

**URL:** <https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243>\
**Category:** Site Management\
**Tags:** how-to, content-security-policy\
**Created:** [December 14, 2018, 4:38pm UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243 "2018-12-14T16:38:20Z")\
**Posts on this page:** 1\
**Showing post:** 25

<div class="post-metadata">

**Author:** ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)\
**Post date:** [June 2, 2020, 4:13pm UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243/25 "2020-06-02T16:13:29Z")

</div>

> [@adrelanos](#):
>
> Could you please add a [Feature-Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy)?

Given that [the spec is still a draft](https://w3c.github.io/webappsec-feature-policy/#feature-policy-http-header-field), I don’t expect us to implement it at this time. The Mozilla website you listed even says:

> The `Feature-Policy` header is still in an experimental state, and is subject to change at any time. Be wary of this when implementing Feature Policy on your website.

---

_[View the full topic](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243)._
