Guide

HSTS, CSP, CORS, and Cache-Control are all headers — and almost everything else about them is different.

They sit next to each other in a response, which makes them easy to lump together. The problem each one solves is completely different.

HSTS tells the browser to come back over HTTPS

Strict-Transport-Security lets supported browsers remember that a site should use HTTPS. On later visits, the browser can avoid an HTTP detour.

Options such as includeSubDomains and preload widen the blast radius, so they make sense only after HTTPS is reliable across the intended scope.

CSP controls where page resources may come from

Content-Security-Policy can restrict sources for scripts, styles, images, frames, and more.

A stricter policy is not automatically a better policy: it can also block legitimate application code. Inventory the resources the site actually uses before tightening it.

CORS is not authentication

CORS is the browser-facing mechanism that tells a cross-origin request which origins, methods, and headers are allowed by the responding server.

Adding Access-Control-Allow-Origin does not decide who a user is or what that user is authorized to do. Authentication and authorization remain separate concerns.

Cache-Control is the one mainly talking about storage and reuse

Cache-Control tells browsers and shared caches whether a response may be stored, for how long, and under what revalidation rules.

It appears in the same header block as HSTS or CSP, but its job is different. Thinking in four labels — HTTPS, resource sources, cross-origin access, caching — is much easier than memorizing a pile of header names.

Related tools

Related topics

References