{"id":27538,"date":"2022-08-22T09:15:10","date_gmt":"2022-08-22T07:15:10","guid":{"rendered":"https:\/\/www.makingscience.com\/?p=27538"},"modified":"2022-08-22T09:15:10","modified_gmt":"2022-08-22T07:15:10","slug":"csp-y-cors-que-son-y-por-que-deberias-usarlas","status":"publish","type":"post","link":"https:\/\/www.makingscience.com\/es\/blog\/csp-y-cors-que-son-y-por-que-deberias-usarlas\/","title":{"rendered":"CSP y CORS: \u00bfQu\u00e9 son y por qu\u00e9 deber\u00edas usarlas?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Es muy probable que en alg\u00fan momento de tu vida hayas escuchado por un motivo u otro nombrar CSP o CORS, o ambas cabeceras HTTP, y que si no aclaraste los conceptos recuerdes que ambas cabeceras de seguridad parecen funcionar de manera similar, pero en realidad no es as\u00ed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Cross<\/strong> <strong>Origin Resource Sharing (CORS)<\/strong> y <strong>Content Security Policy (CSP)<\/strong> son dos cabeceras usadas en el protocolo HTTP que cuando se implementan ayudando a mejorar la seguridad de una aplicaci\u00f3n web.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Podemos decir que ambas cabeceras HTTP (CORS y CSP) permiten gestionar y controlar mediante una \u201cwhitelist\u201d a los propietarios el origen de los recursos en su aplicaci\u00f3n web, y de este modo aumentar la seguridad del activo digital.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>CORS<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Citando a <\/span><a href=\"https:\/\/developer.mozilla.org\/es\/docs\/Web\/HTTP\/CORS\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">MDN Web Docs:<\/span><\/a><\/p>\n<p><i><span style=\"font-weight: 400;\">El Intercambio de Recursos de Origen Cruzado (<\/span><\/i><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/CORS\" target=\"_blank\" rel=\"noopener\"><i><span style=\"font-weight: 400;\">CORS<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">) es un mecanismo que utiliza cabeceras <\/span><\/i><a href=\"https:\/\/developer.mozilla.org\/es\/docs\/Glossary\/HTTP\" target=\"_blank\" rel=\"noopener\"><i><span style=\"font-weight: 400;\">HTTP<\/span><\/i><\/a><i><span style=\"font-weight: 400;\"> adicionales para permitir que un <\/span><\/i><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/User_agent\" target=\"_blank\" rel=\"noopener\"><i><span style=\"font-weight: 400;\">user-agent<\/span><\/i><\/a><i><span style=\"font-weight: 400;\"> obtenga permiso para acceder a recursos seleccionados desde un servidor, en un origen distinto (dominio) al que pertenece. Un agente crea una petici\u00f3n HTTP de origen cruzado cuando solicita un recurso desde un dominio distinto, un protocolo o un puerto diferente al del documento que lo gener\u00f3.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">Es decir, que si desde una p\u00e1gina web realizamos una petici\u00f3n XHR a otra, el navegador internamente inicia con una solicitud de <\/span><span style=\"font-weight: 400;\">OPTIONS<\/span><span style=\"font-weight: 400;\"> de verificaci\u00f3n. Cuando el servidor al que se le ha lanzado la petici\u00f3n responde, verifica la respuesta y eval\u00faa que en la lista de or\u00edgenes permitidos est\u00e1 la web desde la que se lanza la petici\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Algunos encabezados clave enviados como respuesta a la solicitud de <\/span><span style=\"font-weight: 400;\">OPTIONS<\/span><span style=\"font-weight: 400;\"> comentanda anteriormente son:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Access-Control-Allow-Origin:<\/b><span style=\"font-weight: 400;\"> Tendr\u00e1 una lista con los sites permitidos (como si de una whitelist se tratara). Para peticiones desde cualquier sitio se debe especificar \u00ab*\u00bb, de este modo, el acceso al recurso a cualquier origen.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Access-Control-Allow-Methods:<\/b> <span style=\"font-weight: 400;\">Lista de m\u00e9todos HTTP permitidos: PUT, POST, etc.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Access-Control-Request-Headers:<\/b> <span style=\"font-weight: 400;\">Si se establece, las cookies son enviadas por el navegador.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><b>CSP<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Citando a <\/span><a href=\"https:\/\/developer.mozilla.org\/es\/docs\/Web\/HTTP\/CSP\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">MDN Web Docs: <\/span><\/a><\/p>\n<p><em><span style=\"font-weight: 400;\">Pol\u00edtica de Seguridad del Contenido o (CSP) &#8211; del ingl\u00e9s Content Security Policy &#8211; es una capa de seguridad adicional que ayuda a prevenir y mitigar algunos tipos de ataque, incluyendo Cross Site Scripting (XSS) y ataques de inyecci\u00f3n de datos. Estos ataques son usados con diversos prop\u00f3sitos, desde robar informaci\u00f3n hasta la desfiguraci\u00f3n de sitios o distribuci\u00f3n de malware.<\/span><\/em><\/p>\n<p><span style=\"font-weight: 400;\">Es decir, el objetivo principal es proteger frente a los ataques de Cross-Site Scripting (XSS) estableciendo en qu\u00e9 secuencias de comandos se debe confiar y cu\u00e1les no. Cuando un navegador intenta ejecutar un script desde una fuente desconocida, CSP lo bloquear\u00e1.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CSP se establece a trav\u00e9s del encabezado HTTP <\/span><span style=\"font-weight: 400;\">Content-Security-Policy<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una vez explicadas ambas, podemos decir que la diferencia con CORS, es que CORS evita que desde un tercer sitio se acceda a nuestro activo digital, mientras que CSP evita que un sitio web cargue contenido de un tercero.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Para aclarar un poco m\u00e1s cada una de las cabeceras, nos valdremos del siguiente ejemplo.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Supongamos que nuestro website es<\/span> <b><i>mywebsite.com<\/i><\/b><span style=\"font-weight: 400;\"> y que <\/span><b><i>otherwebsite.com<\/i><\/b><span style=\"font-weight: 400;\"> es otro con \u201cmalas intenciones\u201c.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Usando cabeceras CORS evitaremos este tipo de peticiones, ya que <\/span><b><i>otherwebsite.com<\/i><\/b> <span style=\"font-weight: 400;\">no se encuentra en la lista de or\u00edgenes permitidos.<\/span><\/p>\n<p><b>mywebsite.com<\/b><span style=\"font-weight: 400;\"> &lt;&#8212;&#8212;&#8212;&#8212; <\/span><span style=\"font-weight: 400;\">X<\/span><span style=\"font-weight: 400;\"> &#8212;&#8212;&#8212;&#8212; <\/span><b>otherwebsite.com<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><i><span style=\"font-weight: 400;\">\u00a0(mywebsite.com\/style.css)<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">Por otro lado, si tenemos configurada la cabecera CSP en nuestra web, y alguien intenta realizar una llamada desde <\/span><b>mywebsite.com<\/b><span style=\"font-weight: 400;\"> a otra URL que no tenemos permitida, el navegador bloquear\u00e1 dicha petici\u00f3n.<\/span><\/p>\n<p><b>mywebsite.com<\/b><span style=\"font-weight: 400;\"> &#8212;&#8212;&#8212;&#8212; <\/span><span style=\"font-weight: 400;\">X<\/span><span style=\"font-weight: 400;\"> &#8212;&#8212;&#8212;&#8212;&gt; <\/span><b>otherwebsite.com<\/b><\/p>\n<p><i><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0(otherwebsite.com\/script.js)<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>Ahora ya sabes diferenciar CORS y CSP, pero quiz\u00e1s, pueda surgirte alguna duda todav\u00eda. \u00a1No dudes en coment\u00e1rnosla! \ud83d\ude80<\/p><\/blockquote>\n<p style=\"text-align: center;\"><a style=\"border-radius: 15px; padding: 1em; background-color: #f0076f; color: white;\" href=\"https:\/\/www.makingscience.es\/contacto\/\" target=\"_blank\" rel=\"noopener\">Contacta aqu\u00ed<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Es muy probable que en alg\u00fan momento de tu vida hayas escuchado por un motivo u otro nombrar CSP o CORS, o ambas cabeceras HTTP, y que si no aclaraste los conceptos recuerdes que ambas cabeceras de seguridad parecen funcionar de manera similar, pero en realidad no es as\u00ed. Cross Origin Resource Sharing (CORS) y [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":27553,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34],"tags":[302,381,380,301],"class_list":["post-27538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology-ai","tag-cloud-es","tag-cors","tag-csp","tag-seguridad"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts\/27538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/comments?post=27538"}],"version-history":[{"count":0,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts\/27538\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/media\/27553"}],"wp:attachment":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/media?parent=27538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/categories?post=27538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/tags?post=27538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}