Picto thématique

Rule n° 209 - Integrity control of third party resources is present and valid.

It is possible to verify that the third-party resources (files scripts, style sheets ...) have not been modified to insert malicious code. For this, the server will continuously check the sent files are the correct files. This best practice encourages the implementation of this security measure.

#Security #Development

Goal

  • Prevent the appearance of malicious content or scripts on the site

Implementation

Use the integrity attribute of each link and script element (calling an external file) to provide the browser with the cryptographic hash (SRI hash) that should correspond with the file.

Find out more:

Control

Check for each link and script element (calling an external file) that the integrity attribute indicating the cryptographic hash (SRI hash) is present that should correspond with the file.

By Opquast - Read the license