Beveiligingsopties
HTTP security headers
X-Frame-Options
- "7.6 The X-Frame-Options header" in HTML Living Standard
- RFC 7034: HTTP Header Field X-Frame-Options
- X-Frame-Options, MDN webdocs
X-Content-Type-Options
X-XSS-Protection (vervallen)
Content-Security-Policy (CSP)
- Content Security Policy Level 3, W3C Working Draft (In overeenstemming met CSP3 beschouwen we
frame-src
niet als 'deprecated'.) - Content Security Policy Level 2, W3C Recommendation
- Content-Security-Policy, MDN webdocs
- Mozilla's Laboratory (Content Security Policy / CSP Toolkit)
Referrer-Policy
- Referrer Policy, W3C Candidate Recommendation, 26 January 2017
- Referrer Policy, Editor’s Draft
- Referrer-Policy, MDN webdocs