headers by 0x6a03448f4d
← All headers
Isolation

Cross-Origin-Resource-Policy (CORP)

Control who can embed your resources.

What it is

Tells the browser which origins are allowed to load a given resource (script, image, JSON…).

Why it matters

Mitigates cross-site leaks (Spectre-style side channels and resource probing) by refusing cross-origin embedding.

Risk without it

Without CORP, other sites can embed and time your resources to infer information.

Recommended

same-origin for private resources; cross-origin for assets meant to be public.

Set it

add_header Cross-Origin-Resource-Policy "same-origin" always;

References