Content Security Policy
github.com
github.com
<meta http-equiv="Content-Security-Policy" content="default-src *; script-src https://assets.example.com; style-src https://assets.example.com"></meta>
I'm not sure if that introduces any additional attack vectors (other than somebody modifying the document in an unencrypted connection) but it's useful for when hosting statically.EDIT: updated to mimic example in post
You can configure your webserver to add those headers, when hosting statically. There is no need to include it in all your pages.
nginx: add_header Content-Security-Policy "...";
I would recommend using some kind of test in your scripting to see if it's actually working. I purposely attempt to inject a <script> tag to fiddle with a variable. If it works, I know CSP isn't functional in the browser and avoid the dangerous stuff (rendering user-generated content). Otherwise, it's full speed ahead, detailed here: http://rachelbythebay.com/w/2011/10/31/csp/
Hope it help someone.
I'd very much appreciate it if you could point me at things that aren't working in Canary. :)