In short

Cross-site scripting (XSS) remains a top threat to web apps - including Mendix. Learn how Content Security Policy (CSP) provides a powerful, browser-level defense and what directives you should use.