SecurityFrontendHigh signal

Content Security Policy

Also written as CSP

A browser security feature that lets a site declare which sources of scripts, styles, and other content are allowed to load, blocking a large class of cross-site scripting (XSS) attacks.

Think of it like

Like a building's guest list at the front desk — only pre-approved visitors (scripts) are let in, no matter who shows up at the door.

Junior or senior?

Junior sounds like

Knows 'don't trust user input' abstractly but hasn't configured a CSP header.

Senior sounds like

Has configured one themselves and can describe what it broke the first time they turned it on.

Ask them

“Have you configured a Content Security Policy yourself? What did it break the first time you turned it on?”