Articles
How to Fix Your Content-Security-Policy (With Copy-Paste nginx, Apache and Caddy Configs)
A practical guide to building a Content-Security-Policy that works: how CSP is parsed, the directives that matter, and ready-to-paste server configs.
CORS Explained: The Mental Model and the Misconfigurations That Get Exploited
CORS protects users, not your server. The right mental model, the dangerous patterns (origin reflection, wildcard with credentials) and correct configs.
Preventing Clickjacking: X-Frame-Options vs CSP frame-ancestors
How clickjacking works, step by step, and how to stop it with X-Frame-Options and CSP frame-ancestors, with nginx, Apache and Caddy configs.
HSTS Explained: max-age Strategy, includeSubDomains Pitfalls, and the Preload List
A practical HSTS guide: how Strict-Transport-Security works, ramping max-age safely, includeSubDomains pitfalls, preloading, and copy-paste configs.
The Complete Guide to HTTP Security Headers in 2026
The HTTP security headers that matter in 2026 (CSP, HSTS, X-Frame-Options, Permissions-Policy, COOP/COEP), with copy-paste nginx, Apache & Caddy configs.
More topics
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.