Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
HTML

HTML: Use Permissions Policy to Control Browser Features

- 06.06.26 - ErcanOPAK

🔒 Disable Camera, Microphone, Geolocation by Default

Third-party scripts accessing sensitive APIs? Permissions Policy controls which features are allowed. Defense in depth.

📝 HTTP Header

# Disable everything
Permissions-Policy: geolocation=(), camera=(), microphone=(), payment=()

# Allow only same origin
Permissions-Policy: geolocation=(self), camera=(self)

# Allow specific domains
Permissions-Policy: geolocation=(self "https://trusted.com")

# Allow all (default)
Permissions-Policy: geolocation=*

🎯 Permissions Policy Features

- accelerometer
- ambient-light-sensor
- autoplay
- camera
- display-capture
- encrypted-media
- fullscreen
- geolocation
- gyroscope
- magnetometer
- microphone
- midi
- payment
- picture-in-picture
- usb
- wake-lock
- web-share

Example:
Permissions-Policy: camera=(self "https://video-call.com"), microphone=(self "https://video-call.com"), geolocation=()

💡 Use Cases

  • Ad iframes: disable geolocation, camera, microphone
  • Blog comments: disable everything except autoplay
  • Banking site: allow only payment, disable everything else
  • Video call: allow camera, microphone only on video-call subdomain

“Malicious ad iframe tried to access geolocation. Permissions Policy blocked it. Users never saw permission prompt. Security without user friction.”

— Security Engineer

Related posts:

How to apply two classes to a single element in CSS

HTML: Use Picture Element and srcset for Responsive Images

HTML: Use Download Attribute to Force File Download Instead of Opening

Post Views: 4

Post navigation

CSS: Use @property to Define Typed Custom Properties
JavaScript: Use Object.groupBy to Group Arrays Without Lodash

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

June 2026
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930  
« May    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (805)
  • Add Constraint to SQL Table to ensure email contains @ (580)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (579)
  • Average of all values in a column that are not zero in SQL (538)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (505)
  • Find numbers with more than two decimal places in SQL (454)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files
  • Ajax: Add Custom Headers to Fetch Requests
  • JavaScript: Use console.table to Display Arrays as Tables
  • HTML: Use Spellcheck Attribute to Enable Browser Spell Check
  • CSS: Use user-select to Prevent Text Selection
  • Windows 11: Use Snipping Tool for Instant Screenshots

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (805)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com