Concept Flow - Content Security Policy (CSP)
Browser requests webpage
Server sends HTML + CSP header
Browser reads CSP header
Browser loads resources
Check each resource against CSP rules
Load resource
Render page securely
The browser receives a webpage with CSP rules, then checks each resource it loads against these rules, allowing or blocking them to keep the page safe.