Http security

From wikinotes

HTTP security is generally configured in http headers set in the response by the server.

Notes

http cross origin resource sharing CORS
http content security policy CSP