SecurityFrontendHigh signal
Content Security Policy
Also written as CSP
A browser security feature that lets a site declare which sources of scripts, styles, and other content are allowed to load, blocking a large class of cross-site scripting (XSS) attacks.
Think of it like
Like a building's guest list at the front desk — only pre-approved visitors (scripts) are let in, no matter who shows up at the door.
Junior or senior?
Junior sounds like
Knows 'don't trust user input' abstractly but hasn't configured a CSP header.
Senior sounds like
Has configured one themselves and can describe what it broke the first time they turned it on.
Ask them
“Have you configured a Content Security Policy yourself? What did it break the first time you turned it on?”