
When to add a CSP (Content Security Policy)
05/02/24 • 5 min
Should one consider CSP at the very early stage of starting a new website or under what conditions should one consider implementing CSP.
When to add a CSP (Content Security Policy)Should one consider CSP at the very early stage of starting a new website or under what conditions should one consider implementing CSP.
When to add a CSP (Content Security Policy)Previous Episode

Do generated types from OpenAPI spec change testing?
Hey Kent! I've been thinking about something lately. I've worked at a number of different sass companies and something that is always an interesting problem is how we end-to-end test a software application that has a UI.
I love the idea of testing for confidence and, to that end, I've been wondering how we might begin to shift our thinking about confidence testing when we use some communication protocol, like GRPc or OpenAPI to and use those protocols to generate things like static types.
If a backend and frontend are both very well integration tested and the both use auto-generated types from the same spec file, how much e2e testing do we really need? It seems like the spec file would help bridge that confidence gap a lot for us.
I worked at a relatively large sass company once and we had about 300 e2e tests that ran on every PR. It took way too long, but we had a very high level of confidence when we shipped code. We had integration tests too, but I wonder as I reflect on that experience, should we have focused way more on integration tests and integration testing larger features of the software knowing that we had type safety from the communication protocols we used.
Really hoping to hear back from you! I respect your thoughts on testing a lot and I'm a long time consumer of your open source libraries and ideas.
Do generated types from OpenAPI spec change testing?Next Episode

Inspired by Your Work
Hi Kent,
My name is Mahdi Nazari, and I've admired your work for the past year. Your website has been a wellspring of inspiration, particularly your unique lifestyle and the impactful way you're shaping the world. To sum up, I really love it.
As a graduate Geographic Information Systems (GIS) graduate student, I've had the pleasure of utilizing your JS libraries in my projects. They've proven to be invaluable tools.
Currently, I'm embarking on a journey to build my brand, a platform to share my mission, passions, and more. Your approach resonates deeply with me – it offers a compelling way to communicate my values and ignite a spark in others.
If you were starting your brand from scratch today, what pearls of wisdom would you offer someone embarking on a similar path? Is there any course or book or someone who can help me in this path?
Any insights you could provide would be immensely valuable.
Thank you for your time and for the constant inspiration you provide,
Mahdi Nazari
If you like this episode you’ll love
Episode Comments
Generate a badge
Get a badge for your website that links back to this episode
<a href="https://goodpods.com/podcasts/the-call-kent-podcast-356143/when-to-add-a-csp-content-security-policy-51434951"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to when to add a csp (content security policy) on goodpods" style="width: 225px" /> </a>
Copy