# Mitigate XSS Attacks with Content Security Policy

**URL:** https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243
**Category:** Site Management
**Tags:** how-to, content-security-policy
**Created:** [December 14, 2018, 4:38pm UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243 "2018-12-14T16:38:20Z")
**Posts on this page:** 1
**Showing post:** 38

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [July 19, 2021, 7:12pm UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243/38 "2021-07-19T19:12:44Z")

</div>

> [@Falco](#):
>
> This directive will be enabled by default in the next release cycle.

As promised, this feature was just enabled by default: [CSP Frame Ancestors enabled by default](https://meta.discourse.org/t/csp-frame-ancestors-enabled-by-default/197615)

---

_[View the full topic](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243)._
