Service & benefits
Hardened CSP with nonces, strong transport security (HSTS), SRI chain, rate limiting and CSRF checks. Includes fix plan.
Deliverables
Concrete artifacts matching the package: code/configs, brief docs (README/runbook), checklists. Optional recorded walkthrough.
Tech & quality
Strict CSP, clean error handling, reproducible setups. Emphasis on clear interfaces, logs and metrics.
Included scope
- Strict CSP & nonces
- HSTS & TLS hardening
- Rate limit & CSRF protection