# 使用内容安全策略缓解 XSS 攻击

**URL:** https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243
**Category:** Site Management
**Tags:** how-to, content-security-policy
**Created:** [2018年十二月14日 16:38 UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243 "2018-12-14T16:38:20Z")
**Posts on this page:** 1
**Showing post:** 42

<div class="post-metadata">

### Author: ![ReenigneArcher](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/reenignearcher/32/278266_2.png) [@ReenigneArcher](https://meta.discourse.org/u/ReenigneArcher)
#### Post date: [2022年十月25日 22:28 UTC](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243/42 "2022-10-25T22:28:04Z")

</div>

也许我遗漏了什么，但我没有在设置 UI 中看到这些设置。

- `content_security_policy`
- `content_security_policy_report_only`
- `content_security_policy_collect_reports`（我看到它现在被隐藏了）
- `content_security_policy_script_src`

 ![image](https://global.discourse-cdn.com/meta/original/4X/d/0/3/d0318f0aff719551bc44d6f2b1f19f4112417ae3.png)

这些选项是否可用于托管实例？我没有在原始帖子或评论中看到任何关于这是限制的提及。

_编辑：_ 也尝试通过主题设置安全策略。

按照原始帖子中的说明似乎不起作用。

 ![image](https://global.discourse-cdn.com/meta/original/4X/7/e/8/7e84e27a964017438c6b95f35ae5f04d1596aed6.png)

 ![image](https://global.discourse-cdn.com/meta/original/4X/7/7/e/77e194c38c755a9d3aefcd243031cb9f3861e40e.png)

我假设我所在的托管计划不允许这样做，即使是通过主题或主题组件完成的？

或者也许我只是做错了什么。

---

_[View the full topic](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243)._
