Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
W3C Web Security Zero-Trust CDN Defense

Subresource Integrity (SRI) & Content Hashing Studio

Generate cryptographic W3C Subresource Integrity (SRI) hashes (SHA-384/SHA-512). Simulate CDN compromise attacks, test browser crossorigin enforcement, and build zero-trust Content Security Policy directives.

1. Asset Payload & Hash Algorithm

2. Supply Chain Attack Simulator

Browser SRI Verification: PASS (Exact Digest Match)
Expected SRI: sha384-abc...
Received SRI: sha384-abc...
Execution Result: DOM Execution Permitted

Production Deployment Snippets


      

Browser SRI Security Verification Log

\n\n" + "\n" + ""; var cspCode = "# Content Security Policy (CSP) Header with SRI Enforcement\n" + "Content-Security-Policy: require-sri-for script style; default-src 'self'; script-src 'self' https://cdn.example.com;"; var viteCode = "// vite.config.js\n" + "import { defineConfig } from 'vite';\n" + "import sri from 'vite-plugin-sri';\n\n" + "export default defineConfig({\n" + " plugins: [\n" + " sri({ algorithms: ['sha384'] })\n" + " ]\n" + "});"; if (currentTab === "html") snippetBox.textContent = htmlCode; else if (currentTab === "csp") snippetBox.textContent = cspCode; else snippetBox.textContent = viteCode; } btnTamper.addEventListener("click", function() { currentText = originalText + "\n// MALICIOUS PAYLOAD: window.__exfiltrate_keys();"; codePayload.value = currentText; logTrace("ATTACK: Injected malicious payload into CDN asset payload.", "#ef4444"); logTrace("Browser computeSubresourceIntegrity() digest check failed!", "#f59e0b"); logTrace("CRITICAL: Browser aborted script parsing and blocked execution.", "#ef4444"); updateAll(); }); btnRestore.addEventListener("click", function() { currentText = originalText; codePayload.value = originalText; logTrace("Restored original pristine asset payload.", "#10b981"); logTrace("Cryptographic digest match confirmed.", "#34d399"); updateAll(); }); codePayload.addEventListener("input", function() { originalText = codePayload.value; currentText = originalText; updateAll(); }); algoSelect.addEventListener("change", updateAll); var presets = document.querySelectorAll(".preset-asset"); presets.forEach(function(btn) { btn.addEventListener("click", function() { var code = btn.getAttribute("data-code"); codePayload.value = code; originalText = code; currentText = code; logTrace("Loaded asset template: " + btn.textContent, "#94a3b8"); updateAll(); }); }); var tabH = document.getElementById("tabHtmlTag"); var tabC = document.getElementById("tabCspHeader"); var tabV = document.getElementById("tabViteConfig"); function setTab(active, tName) { [tabH, tabC, tabV].forEach(function(b) { b.style.background = "var(--surface)"; b.style.color = "var(--fg)"; }); active.style.background = "#4f46e5"; active.style.color = "white"; currentTab = tName; updateAll(); } tabH.addEventListener("click", function() { setTab(tabH, "html"); }); tabC.addEventListener("click", function() { setTab(tabC, "csp"); }); tabV.addEventListener("click", function() { setTab(tabV, "vite"); }); logTrace("Subresource Integrity (SRI) studio initialized.", "#38bdf8"); updateAll(); })();

Frequently Asked Technical Questions

What is W3C Subresource Integrity (SRI) and how does it prevent supply chain attacks?+
Subresource Integrity (SRI) is a W3C security standard that enables web browsers to verify that resources fetched from external Content Delivery Networks (CDNs) have not been unexpectedly manipulated. When an HTML tag specifies an integrity attribute (e.g., integrity="sha384-..."), the browser hashes the incoming response body before executing it. If the cryptographic digest does not match the expected hash bit-for-bit, the browser refuses to execute the script or apply the stylesheet, thwarting CDN compromises such as the famous Polyfill.io or British Airways Magecart breaches.
Why does W3C recommend SHA-384 over SHA-256 for Subresource Integrity?+
While SHA-256 is cryptographically secure, SHA-384 is derived from SHA-512 by truncating the output, making it immune to length-extension attacks. Furthermore, on 64-bit CPU architectures, SHA-384/SHA-512 executes significantly faster in hardware and optimized software pipelines than 32-bit word SHA-256, providing both higher collision resistance (192 bits vs 128 bits) and superior throughput.
Why is the crossorigin="anonymous" attribute strictly required for cross-origin SRI?+
To prevent cross-origin timing attacks and information leaks, the browser enforces the Cross-Origin Resource Sharing (CORS) protocol whenever integrity validation is applied to a third-party domain. Without crossorigin="anonymous" (or crossorigin="use-credentials"), the browser blocks the resource fetch entirely and logs an error, ensuring that the host server explicitly consents to byte-level inspection.
How does SRI integrate with Content Security Policy (CSP)?+
Using the CSP directive require-sri-for script style, security architects can mandate that every external script or stylesheet referenced on the website MUST have a valid integrity attribute. Any script tag lacking an integrity attribute is blocked immediately by the browser at parse time, establishing a bulletproof zero-trust supply chain defense.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement