How good is the Anti-XSS library from Microsoft?
In the debates between a Content Security Policy vs. the Anti-XSS library from Microsoft, is there a need for both?
It seem the Anti-XSS library from Microsoft will mitigate a variety of potential XSS attacks. But, where is it lacking?
What aspects of CSP are needed when trying to close all the exposures, that the Anti-XSS library from Microsoft does not close?
Thanks