Skip to main content

Security headers guides and articles

Every CompleteStatus blog post tagged Security headers — 5 articles, newest first.

Articles

security-headers csp

How to Fix Your Content-Security-Policy (With Copy-Paste nginx, Apache and Caddy Configs)

A practical guide to building a Content-Security-Policy that works: how CSP is parsed, the directives that matter, and ready-to-paste server configs.

5 min read
cors security-headers

CORS Explained: The Mental Model and the Misconfigurations That Get Exploited

CORS protects users, not your server. The right mental model, the dangerous patterns (origin reflection, wildcard with credentials) and correct configs.

6 min read
security-headers clickjacking

Preventing Clickjacking: X-Frame-Options vs CSP frame-ancestors

How clickjacking works, step by step, and how to stop it with X-Frame-Options and CSP frame-ancestors, with nginx, Apache and Caddy configs.

5 min read
security-headers hsts

HSTS Explained: max-age Strategy, includeSubDomains Pitfalls, and the Preload List

A practical HSTS guide: how Strict-Transport-Security works, ramping max-age safely, includeSubDomains pitfalls, preloading, and copy-paste configs.

6 min read
security-headers csp

The Complete Guide to HTTP Security Headers in 2026

The HTTP security headers that matter in 2026 (CSP, HSTS, X-Frame-Options, Permissions-Policy, COOP/COEP), with copy-paste nginx, Apache & Caddy configs.

7 min read

More topics